Koozali.org: home of the SME Server

Trusted network problem with open vpn

Offline ramasule

  • *
  • 78
  • +0/-0
Trusted network problem with open vpn
« on: June 15, 2009, 07:12:06 AM »
Ok there is a trick to the madness:)
If I start the server without any trusted networks, and then start my openvpn server allowing it to create custom network 192.168.100.0, then I add in the would be custom network 192.168.100.0 to trusted network it works.

However if I have 192.168.100.0 in trusted network when I start openvpn, openvpn is unable to create the route I need and therefore my vpn dosnt work.

I assume the trusted network allows DNS services on the network listed which I need.

So the golden question is... can someone tell me what I need to manipulate to make this work? 

I tried manually adding the route after and that didnt work so I'm assuming its more then just routing table.

If someone can tell me the commands here to make it work I can add it into a script.

My server ip is 192.168.11.1   its openvpn server is 192.168.100.1

My VPN Client is 192.168.12.1  its openvpn address is 192.168.100.4

My 2nd VPN Client is 192.168.14.1 its openvpn address is 192.168.100.8

Here is a link to pastebin of my routing tables in the 4 possible configureations
1. Trusted network then Openvpn  (didnt work)
2. Trusted network no openvpn
3. Openvpn no trusted network    (works for pinging clients but does not have dns / domain     service)
4. Openvpn then trusted network  (works so beautifully I shed a single man tear when I saw it working)

http://pastebin.com/m39786f9b

any suggestions will help no matter how crazy they are,

Thank you for your time,

Derek L

Offline ramasule

  • *
  • 78
  • +0/-0
Re: Trusted network problem with open vpn
« Reply #1 on: June 15, 2009, 04:44:08 PM »
[0:0] -A local_chk_8501 -s 192.168.100.0/255.255.255.0 -j ACCEPT

is the line that I need I belive is there anything else?

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Trusted network problem with open vpn
« Reply #2 on: June 15, 2009, 05:19:16 PM »
Your post is off-topic for this forum, which concerns only software included with SME server CD image.

If you have installed a contrib and it doesn't work correctly (i.e. as you think it should) then you should open a bug in the Bug Tracker, in the Contribs section.

Offline ramasule

  • *
  • 78
  • +0/-0
Re: Trusted network problem with open vpn
« Reply #3 on: June 15, 2009, 08:04:49 PM »
Im asking how to add that permission into the iptable or how to call sme server to do it which is included in the base install of sme server.

Offline ramasule

  • *
  • 78
  • +0/-0
Re: Trusted network problem with open vpn
« Reply #4 on: June 16, 2009, 04:27:32 AM »
I guess what I'm trying to ask is...
how would one invoke that local network command in the gui from bash prompt.
or...
how would one invoke that local network command in the gui from bash prompt and exlude the addition to the routing table.

I have tried the howto and expanding a template but it just dosnt seem to add the rule I need and I'm stumped.

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Trusted network problem with open vpn
« Reply #5 on: June 16, 2009, 03:12:25 PM »
I guess what I'm trying to ask is...

And what I am trying to tell you is that you are asking in the wrong place.

Offline ramasule

  • *
  • 78
  • +0/-0
Re: Trusted network problem with open vpn
« Reply #6 on: June 16, 2009, 04:25:32 PM »
Sorry I thought the firewall was a base issue.

Please close / delete thread
« Last Edit: June 16, 2009, 04:38:50 PM by ramasule »

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Trusted network problem with open vpn
« Reply #7 on: June 16, 2009, 04:43:08 PM »
Sorry I thought the firewall was a base issue.

The base has no firewall rules which are designed to operate correctly with an openvpn contrib.

You should report the problem with the operation of the contrib via the Bug Tracker. If the openvpn contrib developers think there is something in the base which should change, they will open a bug asking for that change.

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: Trusted network problem with open vpn
« Reply #8 on: June 16, 2009, 07:43:58 PM »
Moving to SME 7.x Contribs where it is more appropriate.
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)