How to avoid unencrypted connection to re-appear
Posted: Thu Feb 24, 2011 12:56 pm
Bridged connection is used to encrypt internet traffic between home wifi 192.168.4.1/24 notebook and work network 192.168.91.1/24 both running Windows Vista.
If openvpn client is started, all is ok. "route print" returns:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.91.1 192.168.91.123 30
After some time a line after that automaticaaly appears:
0.0.0.0 0.0.0.0 192.168.4.1 192.168.4.241 25
and internet traffic is sent unencrypted over 192.168.4.1
If second route is manually deleted using
route delete 0.0.0.0 192.168.4.1
uncrypted connection is restored. After some time this line appears again and connection is not encrypted again.
How to force internet access to be encrypted always ?
Andrus.
client config:
client
dev tap
remote mysite.com
persist-key
persist-tun
mute-replay-warnings
ca ca.crt
cert andrus-notebook.crt
key andrus-notebook.key
mute 20
server config:
dev tap
dev-node tap-bridge
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
server-bridge 192.168.91.1 255.255.255.0 192.168.91.123 192.168.91.254
push "redirect-gateway"
push dhcp-option DNS 1.2.3.4
keepalive 10 120
persist-key
persist-tun
mute 20
If openvpn client is started, all is ok. "route print" returns:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.91.1 192.168.91.123 30
After some time a line after that automaticaaly appears:
0.0.0.0 0.0.0.0 192.168.4.1 192.168.4.241 25
and internet traffic is sent unencrypted over 192.168.4.1
If second route is manually deleted using
route delete 0.0.0.0 192.168.4.1
uncrypted connection is restored. After some time this line appears again and connection is not encrypted again.
How to force internet access to be encrypted always ?
Andrus.
client config:
client
dev tap
remote mysite.com
persist-key
persist-tun
mute-replay-warnings
ca ca.crt
cert andrus-notebook.crt
key andrus-notebook.key
mute 20
server config:
dev tap
dev-node tap-bridge
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
server-bridge 192.168.91.1 255.255.255.0 192.168.91.123 192.168.91.254
push "redirect-gateway"
push dhcp-option DNS 1.2.3.4
keepalive 10 120
persist-key
persist-tun
mute 20