openvpn – Openwrt and external vpn server
I Try to setup Openwrt to allow vpn (openvpn) the openvpn server is a vm on LAN (I know is more easy to search on google openwrt+openvpn and then setup..but I had one server already setup and I want to know how to configure openwrt in case of separate vpn server.
The openwrt router is 192.168.0.1, the openvpn server is 192.168.0.8
I have setup a redirect and my client (a pc with another connection on internet) can reach and authenticate to openvpn server. The problem is all packets are filtered
Ping report (from the client)
ping 192.168.0.1
From 10.8.0.1 icmp_seq=... Packet filtered
This is the openwrt firewall config
config redirect
option name 'Vpn1'
option target DNAT
option src wan
option dest lan
option proto tcp
option src_dport 2342
option dest_ip 192.168.0.8
option dest_port 2342
option enabled 1
# Openvpn
config zone
option name 'vpn'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config forwarding
option src 'lan'
option dest 'vpn'
config forwarding
option src 'vpn'
option dest 'wan'
config rule
option target 'ACCEPT'
option proto 'tcp udp'
option dest_port '2342'
option family 'ipv4'
option src '*'
option name 'Allow Inbound vpn'
config rule
option target 'ACCEPT'
option proto 'tcp udp'
option src '*'
option dest '*'
option dest_port '2342'
option family 'ipv4'
option name 'Allow Forwarded vpn'
config rule
option target 'ACCEPT'
option proto 'tcp udp'
option family 'ipv4'
option src '*'
option src_ip '10.8.0.0/24'
option dest_ip '192.168.0.0/24'
option name 'Allow Inbound vpn Traffic to LAN'
config rule
option target 'ACCEPT'
option proto 'tcp udp'
option family 'ipv4'
option src '*'
option src_ip '10.8.0.0/24'
option dest '*'
option dest_ip '192.168.0.0/24'
option name 'Allow Forwarded vpn Traffic to LAN'
config rule
option target 'ACCEPT'
option family 'ipv4'
option proto 'icmp'
option src '*'
option src_ip '10.8.0.0/24'
option dest 'wan'
option name 'Allow Outbound ICMP Echo Request'
list icmp_type 'echo-request'
What I miss?
Thanks
Read more here: Source link