Re: [Openvpn-users] Entering someone's LAN

  • From: Christoph Haas <email@xxxxxxxxxxxxxxxxx>
  • Date: Thu, 12 Oct 2006 20:47:09 +0200

Hi, Karol...

On Thursday 12 October 2006 18:36, Karol Krenski wrote:
> I am a newbie to VPN. Luckly I managed to configure OpenVPN server.

Server? You are probably the OpenVPN "client".

> In 
> our school there are a few LANs (protected with firewalls and NAT) and I
> can access all LANs from outside via school's OpenVPN server.
> The configuration
>    - OpenVPN server tun0
>   - home tun0
> - home eth0
> - home gets natted into this
> My home machine is Then there's router+NAT which I don't
> administer - the traffic to the school from home comes from
> via that - someone's router.
> Now, how should I access home from school? When logged to the OpenVPN
> server I can ping Should I use or
> when pinging home?

Unless the OpenVPN server at school knows that your network is 
192.168.23.?/? you can only reach

> I can't ping - 
> there's no such route configured.

Correct. That would mean the server at school needs an openvpn 
configuration option:

route 192.168.23.? 255.255.255.?

pointing to your OpenVPN tunnel. And of course the school network needs to 
know that your home network is reachable through the openvpn server.

> In school if I am few LANs away from OpenVPN server and starting another
> tunnel there, I can't reach (I can always reach only

Firewalling perhaps? Best bet: talk to the school's openvpn network 
administrators. Bring chocolate.

Good luck.

