Fw: newbie, how to connect 2 nets
Bonno Bloksma <b.bloksma <at> tio.nl>
2009-06-02 11:18:37 GMT
Hi,
Oops should (also) have gone to the
list....
----------<quote>---------------------------------
The push route line lets the server tells the
clients that the 2.0 network is behind the vpn tunnel on the server side. It is
general for all clients and goes into the server.conf
the iroute line does two things:
- lets the server tell the OS that anything for the
1.0 network is behind the vpn tunnel, and
- it also needs to be assigned to a specific client
for the openvpn software to know behind which link it is
The best way for that would be to create an
openvpn\ccd directory. Create a file in that directory with the Certificate CN
name used by the client. So if you have created a certificate with CN=ServerB
then create a file openvpn\ccd\ServerB
In that file needs to be the iroute
line.
As I'm using the Linux version and you will be
using the Windows version make sure the ccd\ServerB file has the correct
extention. For Linux there must be no extention, I don't know what it needs to
be for the Windows version.
For the routing part remember that first the OS
needs to know where to route each ip-address. But also openvpn does need to
route internally to make sure each packet ends up at the proper tunnel. With a
two node setup it is a given, but openvpn can handle a lot more.

By telling
openvpn what and how to route your part is done, openvpn will tell the
OS.
The way I have it set up is to push route
172.16.0.0 255.255.0.0 eventhough the server is on a smaller network. That way
everything not part of the network at the specific node will end up at the
server where openvpn or the OS will know what to do with it. Each node is
responsible for its own part of the 172.16.x.0 network, the server handles the
rest.
Met vriendelijke groet,
Bonno Bloksma
senior
systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof
8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35 20
----- Original Message -----
Sent: Friday, May 29, 2009 6:05 PM
Subject: Re: [Openvpn-users] newbie, how
to connect 2 nets
do I need to put route 172.16.2.0 255.255.255.0 on
server.ovpn and iroute 172.16.1.0 255.255.255.0 on
client.ovpn?
----- Original Message -----
Sent: Friday, May 29, 2009 10:27
PM
Subject: Re: [Openvpn-users] newbie,
how to connect 2 nets
Hi,
I would suggest tun as that is the easiest to
setup to connect two networks, or even a few moer sites with just one
connection per site.
We use 172.16.x.x throughout. I have reserved
172.16.0-7.x for routing networks. In my case we use 172.16.1.x for any
OpenVPN tunnel.
Have the server at one site route all traffic
for the other network through the tunnel using standard ip routing rules and
vice versa.
I happen to use tap on my sites to site tunneld
but that is because I have several sites and we use OSPF site to site
routing as backup to the Entended Ethernet lines. In that case it is easier
to use tap as it is then all just an ethernet network.
But endusers have a tun tunnel.
Met vriendelijke groet,
Bonno
Bloksma
senior systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237 35
20
----- Original Message -----
Sent: Friday, May 29, 2009 4:47
PM
Subject: Re: [Openvpn-users] newbie,
how to connect 2 nets
what you suggest tun or tap for doing this
?
----- Original Message -----
Sent: Friday, May 29, 2009 9:04
PM
Subject: Re: [Openvpn-users]
newbie, how to connect 2 nets
Hi,
One would the server, the other the client.
It does not realy matter in a 2 node setup which is which.
Of course be aware of firewalls. If one
server is behind a firewall that blocks incoming traffic then that one
must be the client or you need to open up the openvpn port on the
firewall.
Met vriendelijke groet,
Bonno
Bloksma
senior systeembeheerder
tio
hogeschool hospitality en toerisme
begijnenhof 8-12 / 5611 el eindhoven
t 040 296 28 28 / f 040 237
35 20
----- Original Message
-----
Sent: Friday, May 29, 2009 2:48
PM
Subject: [Openvpn-users] newbie,
how to connect 2 nets
Dear All,
I have
2 networks (Net A and Net B) at different locations, Net A is on
172.16.1.0/24 and Net B is on 172.16.2.0/24
I plan to
implement openvpn 2.1 on Windows 2003 server, how to connect Net A
& B? .. which one would be as server A or B?
Thanks
& Regards
Winanjaya
------------------------------------------------------------------------------
Register
Now for Creativity and Technology (CaT), June 3rd, NYC. CaT
is a
gathering of tech-side developers & brand creativity
professionals. Meet
the minds behind Google Creative Lab, Visual
Complexity, Processing, &
iPhoneDevCamp as they present
alongside digital heavyweights like Barbarian
Group, R/GA, &
Big Spaceship. http://p.sf.net/sfu/creativitycat-com
_______________________________________________
Openvpn-users
mailing list
Openvpn-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users
------------------------------------------------------------------------------
Register
Now for Creativity and Technology (CaT), June 3rd, NYC. CaT
is a
gathering of tech-side developers & brand creativity professionals.
Meet
the minds behind Google Creative Lab, Visual Complexity,
Processing, &
iPhoneDevCamp as they present alongside digital
heavyweights like Barbarian
Group, R/GA, & Big Spaceship.
http://p.sf.net/sfu/creativitycat-com
_______________________________________________
Openvpn-users
mailing
list
Openvpn-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users
------------------------------------------------------------------------------
OpenSolaris 2009.06 is a cutting edge operating system for enterprises
looking to deploy the next generation of Solaris that includes the latest
innovations from Sun and the OpenSource community. Download a copy and
enjoy capabilities such as Networking, Storage and Virtualization.
Go to: http://p.sf.net/sfu/opensolaris-get
_______________________________________________
Openvpn-users mailing list
Openvpn-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users