What's new

OpenVPN site-to-site problems

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

AbOrigine

Occasional Visitor
Hi Everyone,
My first post here.
I have three Asus AC68U's running Merlin's latest firmware (380.64_2).
I successfully connected two clients to one openvpn server, both clients can ping and access server.
I am trying to setup a site-to-site configuration now, in order for server to be able to access clients as well, and for clients to access each other through server.
I have read number of posts, this one seems to be most thorough with a solution, but I am not able to implement it: https://www.snbforums.com/threads/o...clients-lan-on-site-to-site-connection.24268/

My problem is, that I don't seem to have /jffs/configs/openvpn/ccd1/ directory, in fact /jffs/configs directory is empty in all of these three routers. I guess I need to insert iroute 192.168.1.0 255.255.255.0 (with my client's IP's) in "client" file under "/jffs/configs/openvpn/ccd1/" directory on openvpn server and also add "route 192.168.1.0 255.255.255.0 push "route 192.168.1.0 255.255.255.0" (with my client IP's) on openvpn's custom configuration, under advanced settings in GUI.
I have enabled Enable JFFS custom scripts and configs in Admin page, as well as formatted JFFS partition but still no luck.
I am a newbie to Linux and I might be missing something.

Would appreciate your help in this.

And Merlin, thanks for a superb firmware!

Thanks
 
Anyway, I created configs and ccd1 directories, created "client" file, entered iroute "IP of remote lan" 255.255.255.0, added
route remote LAN IP 255.255.255.0 push "route remote LAN IP 255.255.255.0" in Custom Configuration on server side and now server can see clients (I have two clients connected to server via OpenVPN".
Now clients can see server and server can see clients (ping and etc.) but clients can not see each other (server must be blocking them).
Any workaround on this?
Maybe I should add route on client side for remote client (via server?)

Continuing this post on: https://www.snbforums.com/threads/o...s-lan-on-site-to-site-connection.24268/page-4
 
Last edited:

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top