Differences

This shows you the differences between two versions of the page.

inbox:vpn.howto [2014/02/21 21:40]
inbox:vpn.howto [2014/07/09 01:47] (current)
masnia
Line 1: Line 1:
 +====== OpenVPN server ======
 +| :!: There are many redundant wiki pages relating to configuring OpenVPN on OpenWrt.  Some are better than others, and others are an out-of-date muddled mess.  For a reasonably complete / up-to-date guide to installing, configuring and troubleshooting OpenVPN clients & servers on OpenWrt (including creating a simple PKI), could I suggest you consider starting with [[doc/howto/vpn.openvpn]] instead of this wiki. :!: |
 +
 +It is not that the other wikis aren't worth reading; it is just that (IMHO) [[doc/howto/vpn.openvpn]] is a better place to start (it has been rewritten from scratch just a few weeks ago). 
 +
 +Although this wiki does cover some material not covered in [[doc/howto/vpn.openvpn]] (e.g. non-OpenWrt clients), it might still be a useful place to visit.  Maybe you could improve it further rather than edit this wiki?
 +
|FIXME: Please read [[doc/howto/vpn.overview]] and see this old articles on this matter: [[http://wiki.openwrt.org/?do=search&id=vpn]] and help **migrate** them. Check also [[doc:howto:vpn.openvpn]] | |FIXME: Please read [[doc/howto/vpn.overview]] and see this old articles on this matter: [[http://wiki.openwrt.org/?do=search&id=vpn]] and help **migrate** them. Check also [[doc:howto:vpn.openvpn]] |
Line 84: Line 91:
        option 'verb' '3'         option 'verb' '3'
        option 'server' '10.0.0.0 255.255.255.0'         option 'server' '10.0.0.0 255.255.255.0'
 +        option 'client_to_client' '1'
        list 'push' 'redirect-gateway def1'         list 'push' 'redirect-gateway def1'
-        list 'push' 'dhcp-option DOMAIN lan' 
        list 'push' 'dhcp-option DNS 192.168.1.1'         list 'push' 'dhcp-option DNS 192.168.1.1'
 + list 'push' 'route 192.168.1.0 255.255.255.0'
 +</code>
 +If there are [[https://openvpn.net/index.php/open-source/documentation/howto.html#revoke|revoked cerficates]] add also
 +<code>
 +option 'crl_verify' '/etc/easy-rsa/keys/crl.pem'
</code> </code>
Line 111: Line 123:
dh /etc/easy-rsa/keys/dh1024.pem dh /etc/easy-rsa/keys/dh1024.pem
 +client-to-client
server 10.0.0.0 255.255.255.0 server 10.0.0.0 255.255.255.0
push "redirect-gateway def1" push "redirect-gateway def1"
push "dhcp-option DNS 192.168.1.1" # Change this to your router's LAN IP Address push "dhcp-option DNS 192.168.1.1" # Change this to your router's LAN IP Address
-client-to-client+push "route 192.168.1.0 255.255.255.0" # Change this to your network
### (optional) compression (Can be slow) ### (optional) compression (Can be slow)
Line 196: Line 209:
persist-tun persist-tun
persist-key persist-key
-verb 3''|+verb 3 
 +''|
===== Client Usage GNU/Linux - Download OpenVPN ===== ===== Client Usage GNU/Linux - Download OpenVPN =====

Back to top

inbox/vpn.howto.1393015235.txt.bz2 · Last modified: 2014/02/21 21:40 (external edit)