|
|
these are free subnets in our country. we only allow users to visit these subsets through the VPN, and users' default gateway can reach the rest of the network, so we cannot set the VPN as the default gateway. we can write a shell script to add the routes, but if the network error occurs(e.g. the switch down), the route table will be refreshed, then openvpn reconnect to the server without run the script first. ======= 2005-06-03 18:33:13======= >On 6/2/05, 冷晓翔 <xleng@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote: >> Thanks very much >> I don't know how to condense them into summary routes. >> the routes are as follows: >> route 58.24.0.0 255.254.0.0 >> route 59.64.0.0 255.240.0.0 >> route 60.0.0.0 255.224.0.0 >> route 60.63.0.0 255.255.0.0 >> route 60.191.2.0 255.255.255.0 >[snip] >> route 61.200.81.134 255.255.255.254 >> route 61.200.81.136 255.255.255.254 >> route 61.200.81.142 255.255.255.254 >> route 61.200.81.144 255.255.255.254 >> route 61.200.81.150 255.255.255.254 >[snip] >> route 63.208.195.68 255.255.255.255 >> route 63.211.40.87 255.255.255.255 >> route 64.4.240.0 255.255.252.0 >[snip] > >These routes are all over the place. Are you actually allocated these >subnets in larger chunks and these the only subnets in use currently? >If so use the larger subnets to minimize the routes. > >What is your VPN architecture? Can you send different subsets of the >routes to different sites? > >What about using OSPF or RIP to redistribute the routes? using Quagga >(http://www.quagga.net)? >-- >Leonard Isham, CISSP >Ostendo non ostento. > > = = = = = = = = = = = = = = = = = = = = /************************************************************************/ /* Leng Xiaoxiang */ /* Department of Computer Science and Technology */ /* 13#229, Tsinghua University */ /* Beijing 100084, China */ /* xleng@xxxxxxxxxxxxxxxxxxxxxxxxxx */ /* http://leoxiang.net9.org */ /************************************************************************/ ???????????????????????甸?X?????j(?懋?r)??t?? 朕?^???????.???t?? ?)茛??ü僻n瑗u???????㈥杪p)??亘??拳?i??鳐??&、?z?~}???,?贳m4??????????????????:???谦??)?+-:???谦躇b槽??q玷???囤l????.?????X?襄?b???Ь?呵? Warning: require_once(../../../archive_common.php) [function.require-once]: failed to open stream: No such file or directory in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2005-06/msg00049.html on line 235 Fatal error: require_once() [function.require]: Failed opening required '../../../archive_common.php' (include_path='/usr/local/lib/php') in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2005-06/msg00049.html on line 235 |