OpenVPN routing

adiavr_at_gmail.com
Date: 03/24/05


Date: 24 Mar 2005 12:59:32 -0800

Hello,
I have a 192.168.0.x network with a default gateway at 192.168.0.254
which also has an external IP address. I have set up a OpenVPN server
on a secondary gateway at 192.168.0.252 which also has an external IP
address. OpenVPN is running in routing mode, with clients drawing
addresses from the default 10.8.0.0 network.
I can connect from outside fine using the vpn client to the OpenVPN
server and can ping 10.8.0.1, ssh into it, whatever. However, I cannot
get past it to go into the 192.168.0.x network (i.e. 192.168.0 ping
replies are not coming back, although they are being sent from the
respective machines).
Does anyone have any experience with this? I assume this would work
correctly if I just set up OpenVPN on the default 192.168.0.254
gateway, but I thought I'd keep it separate because I can also use it
as a hot spare in the case the default gateway fails. Both systems are
running OpenBSD with PF/NAT.

This seems to be a routing issue.
Ideally I want to have packets go from the client, to the VPN gateway,
then to the default gateway, then to the machines in 192.168.0.x. Then
these machines would follow the same route back.

Really sorry if this is confusing, let me know if I need to give more
information.



Relevant Pages

  • Re: Aktuelle VPN =?ISO-8859-15?Q?L=F6sung_gesucht?=
    ... Im Prinzip nicht, nur auf ein zweites, selbst konfiguriertes Gateway. ... OpenVPN? ... FreeS/WAN war die IPSEC Implementierung bevor IPSEC in den Linuxkernel ...
    (de.comp.os.unix.linux.misc)
  • Re: Ereignis 14147
    ... dann entferne von allen Karten das Gateway. ... > Weil ich mich mit OpenVPN ein bißchen auskenne und da die Verschlüsselung ... Next by Date: ...
    (microsoft.public.de.german.isaserver)
  • Re: [SLE] connection redundancy
    ... which is the router just this side of the ... >>because it's own gateway is still up. ... You'll also need three network cards to put into this Linux box. ... your internal LAN can route packets to the Internet. ...
    (SuSE)
  • Re: Cant access secure Web pages
    ... and which need to be contacted via the Default Gateway. ... The Default Gateway being the software process that does the network ... Gateway (as set up by your ISP's DHCP packet to the router), ... me so I can send it directly (to the MAC address discovered by ARP). ...
    (uk.comp.sys.mac)
  • Re: Problem with Cable Moden & Router.
    ... gateway is the way in or out. ... a gateway leads to another network. ... Where two routes with different network masks overlap ...
    (comp.os.linux.misc)