Many thanks, i use TUN interface and NAT creates by default enabled so nothing to do as i understoodIIRC If your VPN client is using a TUN interface type the connection creates a NAT tunnel by default. Therefore unsolicited incoming connections can't reach the LAN. If you have disabled the NAT tunnel are using a TAP interface type that's a different matter.
IIRC If your VPN client is using a TUN interface type the connection creates a NAT tunnel by default. Therefore unsolicited incoming connections can't reach the LAN. If you have disabled the NAT tunnel or are using a TAP interface type that's a different matter.
My recollection was that the VPN client implementation in John's firmware (which the OP is using) was slightly different than Merlin's. That's why I prefaced my reply with "IIRC".NAT does NOT prevent unsolicited incoming traffic over the OpenVPN client. That's the reason the Inbound Firewall setting was added, which is set to Block by default.
My recollection was that the VPN client implementation in John's firmware (which the OP is using) was slightly different than Merlin's. That's why I prefaced my reply with "IIRC".
I've dug out my old router with John's firmware and tried to test this. I can see that there is indeed no firewall rule that blocks traffic from the tun interface. But try as I might I am unable to create a scenario where the server side can initiate a connection to something on the client's LAN. There just isn't the routing setup on the server side to do this. Even when I create static routes I can't make it work. That's not to say it isn't possible, just that I've not managed to do it.
I guess it might depend on what kind of client-server setup the OP is talking about. Is he connecting to a commercial VPN provider (e.g. NordVPN) or is this a LAN to LAN setup.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!