OPENVPN /IPTABLES help

Wayne Feick waf at brunz.org
Thu Nov 6 20:03:08 UTC 2008


Does dropping the MASQUERADE change things at all?



On Thu, 2008-11-06 at 09:28 +0100, woodson2 wrote:

> Hello, I have openvpn up and running successfully on FC9. I'm using
> routing mode with the following configuration
> 
> My internal LAN range 10.10.10.0/24
> My Openvpn client range 10.8.0.0/24
> 
> I can connect and ping the openvpn server from the openvpn client but
> can't talk to the other machines on the internal LAN subnet. However,
> the machines on the internal LAN subnet can ping the openvpn clients.
> I have entered the following in iptables.
> iptables -t nat -I POSTROUTING -s 10.10.10.0/24 -o eth0 -j MASQUERADE
> iptables -I INPUT -i tun+ -j ACCEPT
> iptables -I INPUT -i tap+ -j ACCEPT
> iptables -I FORWARD -i tap+ -j ACCEPT
> iptables -I FORWARD -i tun+ -j ACCEPT
> iptables -I INPUT -i eth0 -j ACCEPT
> iptables -I FORWARD -i eth0 -j ACCEPT
> I have also added a route on my d-link router that routes any traffic
> destined to 10.8.0.0/24 back to the OPENVPN server(10.10.10.xxx). This
> all works as it should when the firewall is disabled so apparently I'm
> missing some rule in iptables...Any help would be greatly
> appreciated..thanks..
> 
> 
> 
> -- 
> This is an email sent via The Fedora Community Portal https://fcp.surfsite.org
> https://fcp.surfsite.org/modules/newbb/viewtopic.php?post_id=301697&topic_id=63522&forum=10#forumpost301697
> If you think, this is spam, please report this to webmaster at fcp.surfsite.org and/or blame mlstarling31 at hotmail.com.
> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20081106/3b69f50c/attachment-0001.htm>


More information about the fedora-list mailing list