I've gotten myself nice and confused. I have an 87U and .65 with two openvpn servers setup, one for TAP and one for TUN. I normally use the TUN one, in two different ways. One is from a secure second location, using RDP to control a computer on the 87U side; generally I want internet traffic not to go over the tunnel. The other is at insecure locations, mostly public wifi. There I want internet traffic always to go over the tunnel.
I think I can do this with the server set to redirect internet traffic and two different client config files, one exported from the server and one with either route-nopull or route-noexec.
Or, should I set the server not to redirect internet traffic and add the three pushed options (i.e., redirect-gateway def1) to one of the client files.
Or does it matter?
I think I can do this with the server set to redirect internet traffic and two different client config files, one exported from the server and one with either route-nopull or route-noexec.
Or, should I set the server not to redirect internet traffic and add the three pushed options (i.e., redirect-gateway def1) to one of the client files.
Or does it matter?