I want to push a /32 route to the client so they can only access that single IP, but of course nothing prevents them from filtering that route and installing a /24 route to reach the whole subnet.
To protect against this, does openvpn have some config option or should it be done with iptables outside of openvpn?
Limiting client routing table?
Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech
Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
-
- OpenVPN Protagonist
- Posts: 11138
- Joined: Fri Jun 03, 2016 1:17 pm
Re: Limiting client routing table?
The FOSS Openvpn-ce cannot control a wayward client.
The protection you require must be configured on the server side.
The protection you require must be configured on the server side.