Openvpn (IPv4) over IPv6 connection Site to Site
Posted: Sat Jul 08, 2017 8:51 am
Hello together,
i have successfully created a OpenVPN connection. My Client can reach all subnets from the server. But my server cannot reach the subnet from the client.
OpenVPN Server Config
iptables Configuration Server
They are also some other forwarding for the other subnets which are reachable for the client
OpenVPN Client configuration
Client iptables
Help me. I have no plan why my server cannot reach the client subnet.
i have successfully created a OpenVPN connection. My Client can reach all subnets from the server. But my server cannot reach the subnet from the client.
OpenVPN Server Config
Code: Select all
port 1194
proto udp6
dev tun0
sndbuf 0
rcvbuf 0
client-to-client
ca /etc/openvpn/main-keys/ca.crt
cert /etc/openvpn/main-keys/server.crt
key /etc/openvpn/main-keys/server.key
dh /etc/openvpn/main-keys/dh2048.pem
topology subnet
server 10.8.0.0 255.255.255.0
push "route 10.0.1.0 255.255.255.0"
route 10.0.0.0 255.255.255.0 10.8.0.4 #(Client Network)
keepalive 10 120
cipher AES-128-CBC
comp-lzo
user nobody
group nogroup
persist-key
persist-tun
status openvpn-status.log
verb 3
status main-status.log
ifconfig-pool-persist /etc/openvpn/main-ipp.txt
Code: Select all
iptables -A INPUT -i br0 -m state --state NEW -p udp --dport 1194 -j ACCEPT
iptables -A INPUT -i tun0 -j ACCEPT
iptables -I FORWARD -i tun0 -o br0 -j ACCEPT
iptables -I FORWARD -i br0 -o tun0 -j ACCEPT
iptables -t nat -A POSTROUTING -j MASQUERADE
OpenVPN Client configuration
Code: Select all
client
dev tun
proto udp6
auth-nocache
topology subnet
remote <IPv6 ADDRESS OF SERVER> 1194
route 192.168.2.0 255.255.255.0 # all reachable subnets
route 10.242.2.0 255.255.255.0
route 10.9.0.0 255.255.255.0
#resolv-retry infinite
#nobind
cipher AES-128-CBC
comp-lzo
tls-client
persist-key
persist-tun
verb 3
Code: Select all
# Generated by iptables-save v1.4.21 on Sat Jul 8 08:48:41 2017
*filter
:INPUT ACCEPT [8588:4494440]
:FORWARD ACCEPT [25:3068]
:OUTPUT ACCEPT [4606:472037]
-A INPUT -p udp -m udp --dport 1194 -j ACCEPT
-A FORWARD -i tun0 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o tun0 -j ACCEPT
COMMIT
# Completed on Sat Jul 8 08:48:41 2017
# Generated by iptables-save v1.4.21 on Sat Jul 8 08:48:41 2017
*nat
:PREROUTING ACCEPT [816:104716]
:INPUT ACCEPT [721:85047]
:OUTPUT ACCEPT [285:21638]
:POSTROUTING ACCEPT [1:60]
-A POSTROUTING -o tun0 -j MASQUERADE
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Sat Jul 8 08:48:41 2017
# Generated by ip6tables-save v1.4.21 on Sat Jul 8 08:49:19 2017
*nat
:PREROUTING ACCEPT [4:1004]
:INPUT ACCEPT [4:1004]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -j MASQUERADE
COMMIT
# Completed on Sat Jul 8 08:49:19 2017
# Generated by ip6tables-save v1.4.21 on Sat Jul 8 08:49:19 2017
*filter
:INPUT ACCEPT [3143:2333463]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [10873:1377069]
-A INPUT -p udp -m udp --dport 1194 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
COMMIT
# Completed on Sat Jul 8 08:49:19 2017