Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Closed

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
9 posts • Page 1 of 1
Author
Message
dave-gallagher
n00b
n00b
Posts: 29
Joined: Wed Mar 01, 2006 2:01 am

Closed

  • Quote

Post by dave-gallagher » Fri Dec 01, 2006 7:35 pm

Last edited by dave-gallagher on Fri Jan 13, 2023 1:43 am, edited 4 times in total.
Top
sp7xfq
n00b
n00b
User avatar
Posts: 60
Joined: Wed Dec 28, 2005 10:01 am
Location: Poland, Kielce

  • Quote

Post by sp7xfq » Sat Dec 02, 2006 6:37 pm

Hi,

You have configured `redirect-gateway` in your openvpn config file, this means that remote clients treats your server as default network gateway and your server should redirect its packets to the Internet. To do this you should also set packet forwarding:

Code: Select all

echo 1 > /proc/sys/net/ipv4/ip_forward
Or I think (I've not tested this) maybe setting route-gateway to the same as default route in your server will be enough.

And about your ping tests, there is simple explanation for this behaviour. When you run ping command at first it got from the system some variables, among other things routing table, and it use these as long as it running. So, next you are establishing VPN tunnel which change routing table, especially default gateway, but running ping, does not ``know`` about it since it got this as startup.
br.
Andrzej Sobczyk


Feel free to correct my English
Top
thesnowman
Guru
Guru
Posts: 365
Joined: Thu May 08, 2003 3:29 pm
Location: Sydney, Australia

  • Quote

Post by thesnowman » Sun Dec 03, 2006 1:19 am

I think the problem is your

Code: Select all

push "redirect-gateway def1"
line. How do the clients know the IP address of def1? Do they have it hardcoded in the their hosts file?

Also, the reason your dhcp-option DNS line isn't working is because it only works out-of-the-box on windows clients. Non-windows clients require a client-side up script to interpret the dhcp-options and configure the clients appropriately.

It would also be quite trivial to port the bridging script to be more gentoo specific and use the baselayout network scripts to bring it up.
Top
sp7xfq
n00b
n00b
User avatar
Posts: 60
Joined: Wed Dec 28, 2005 10:01 am
Location: Poland, Kielce

  • Quote

Post by sp7xfq » Sun Dec 03, 2006 7:11 am

Hi, thesnowman

Due to openvpn manual the `def1` flag is correct.
`man openvpn` wrote:Add the def1 flag to override the default gateway by using 0.0.0.0/1 and 128.0.0.0/1 rather than 0.0.0.0/0.
This has the benefit of overriding but not wiping out the original default gateway.
Using the def1 flag is highly recommended, and is currently planned to become the default by OpenVPN 2.1.
Andrzej Sobczyk


Feel free to correct my English
Top
thesnowman
Guru
Guru
Posts: 365
Joined: Thu May 08, 2003 3:29 pm
Location: Sydney, Australia

  • Quote

Post by thesnowman » Sun Dec 03, 2006 9:08 pm

Sorry sp7xfq, I should have looked that up before replying.

What does the route command say when you are connected to the VPN?

What about your log files when the clients connect? OpenVPN should be logging the fact that it is changing the default gateway on the client. You may need to increase your verbosity to see this...
Top
dave-gallagher
n00b
n00b
Posts: 29
Joined: Wed Mar 01, 2006 2:01 am

  • Quote

Post by dave-gallagher » Sun Dec 03, 2006 9:29 pm

Last edited by dave-gallagher on Fri Jan 13, 2023 1:36 am, edited 2 times in total.
Top
dave-gallagher
n00b
n00b
Posts: 29
Joined: Wed Mar 01, 2006 2:01 am

  • Quote

Post by dave-gallagher » Sun Dec 03, 2006 10:31 pm

Last edited by dave-gallagher on Fri Jan 13, 2023 1:36 am, edited 2 times in total.
Top
dave-gallagher
n00b
n00b
Posts: 29
Joined: Wed Mar 01, 2006 2:01 am

  • Quote

Post by dave-gallagher » Sun Dec 03, 2006 10:56 pm

Last edited by dave-gallagher on Fri Jan 13, 2023 1:36 am, edited 2 times in total.
Top
thesnowman
Guru
Guru
Posts: 365
Joined: Thu May 08, 2003 3:29 pm
Location: Sydney, Australia

  • Quote

Post by thesnowman » Tue Dec 05, 2006 3:40 pm

On Linux the route command with no arguments will print the routing table. On Windows you need to use "route print". Not sure about OS X.

I'm not sure why you think your default gateway is 10.33.3.250. Both trace routes show 172.17.1.1 as being the default gateway and this is the ip address being pushed by the OpenVPN server as shown in this line:

Code: Select all

Sun 12/03/06 05:51 PM: gw 172.17.1.1
Also, why is your OpenVPN server given an address of 10.33.3.5? Shouldn't it be in the 172.17.1.0/24 range so it can talk to the Linksys?

I don't see how you can be testing this from your LAN. You said you are VPN'ing to your ISP (PPTP?) and then connecting back to your public IP. How does this work? To accurately test this I would suggest testing from a completely separate network with internet access.
Top
Post Reply

9 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic