[OpenVPN home] [Date Prev] [Date Index] [Date Next]
[OpenVPN mailing lists] [Thread Prev] [Thread Index] [Thread Next]
Google
 
Web openvpn.net

Re: [Openvpn-users] Natting a Tun device


  • Subject: Re: [Openvpn-users] Natting a Tun device
  • From: Jon Bendtsen <jon.bendtsen@xxxxxxxxxx>
  • Date: Sat, 15 Jan 2005 10:03:27 +0100

Den 15. jan 2005, kl. 9:09, skrev Waleed Khan:

Hi There,

Here is my scenario. I have a linux vpn server with a public ip address.
I'm running openvpn 2.0.15-1 beta. On the client side i've got another
linux machine connected via a dsl modem to the public internet. The dsl
router is a netgear router running nat. It's private address is
192.168.0.254. I have no problem with the client linux machine talking to
the vpn server. What i'm trying to do is to get the windows boxes sitting
behind the linux machine to talk to the machines on the same network as
the vpn server. What i've done is i'm natting the tun device in iptables
on the client linux server side. The connection from my windows boxes
using the linux client as a default gateway seems unstable. When i SSH
into machines on the same network as the vpn server it logs in , then
freezes after a type a few commands. Same with other applications , they
tend to freeze after a few seconds. I'm wondering if my set up is correct.
Should i nat the tun device to allow my windows boxes behind the linux
client vpn machine to access the other side or is there a more reliable
way if doint this ? Here are the route commands i am using on my linux
client vpn machine.


#!/bin/sh
/sbin/route add -host 196.1.2.5 (remote vpn server) gw 192.168.0.254 (adsl
router ip)
/sbin/route add -net 196.1.2.0(vpnserver's network address) netmask
255.255.255.0 gw 10.0.2.2 (remote vpn private ip)

you have to do the routing in both ends.

network 192.168.0.0/24
    |
gw 192.168.0.1
also running openvpn server 192.168.1.1
   |
openvpn client 192.168.1.2
also gw 192.168.2.1
  |
network 192.168.2.0/24


both GW's needs to know where to find the network for the other end.



JonB



-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt
_______________________________________________
Openvpn-users mailing list
Openvpn-users@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/openvpn-users