Question regarding openvpn and ccd
Hi,
I have a working openvpn install. However, I am seeing multiple packet drops related to non-routable IP addresses. I understand that I can assign a route using ccd for clients sitting behind a router. My problem is that the clients gateway / router can change. So, in a case where a client connects at a hotspot local to them, I have no control over what their actual ip is. An example : Code:
openVPN-GATEWWAY <--> HOTSPOT <--> ( some public facing ip ) <--> CLIENT --( private ip space / rfc1918 ) Code:
gerp/66.123.200.100:28693 MULTI: bad source address from client [192.168.1.125], packet dropped Code:
iroute 192.168.4.0 255.255.255.0 Code:
iroute 192.168.4.21 255.255.255.255 Can I not also add the route to the client_config-directory file? Or does that have to go in the servers config? Since* this would be dynamic, not sure how openVPN would know about the added route if its not reloaded. Reloading the whole daemon for each client connect seems like a no. Would appreciate any input. |
so are you wanting to restrict access by vpn clients to only 192.168.4.21? if so iptables can do it:
Code:
. |
HI,
Actually I am trying to configure it to map the clients "actual" ip. It not that I wish to map traffic to the client. I am seeing drops related to openvpn not having a route to a private IP range. The clients may or may not be sharing something. In this case I am only looking to address the drop of packets. A log example : Code:
Sat Nov 2 12:14:59 2013 us=533871 gerp/24.205.70.162:46482 MULTI: bad source address from client [192.168.5.3], packet dropped Being that I just set up freeRADIUS and mysql to act as the part or the authentication process, I am just trying to make sure I have covered all my bases. I understand that I may confusing; however, much of this is realted to me not knowing what I dont know. I mean, if the clients default gateway is set to the vpn, the only way I would be seeing the clients actual IP as it is behind its AP I can only assume something is very wrong. |
All times are GMT -5. The time now is 11:58 PM. |