From owner-freebsd-net@FreeBSD.ORG Wed Aug 6 19:00:42 2008 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id CA8FE106567F for ; Wed, 6 Aug 2008 19:00:42 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from mx00.pub.collaborativefusion.com (mx00.pub.collaborativefusion.com [206.210.89.199]) by mx1.freebsd.org (Postfix) with ESMTP id 733BA8FC2E for ; Wed, 6 Aug 2008 19:00:42 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from vanquish.ws.pitbpa0.priv.collaborativefusion.com (vanquish.ws.pitbpa0.priv.collaborativefusion.com [192.168.2.162]) (SSL: TLSv1/SSLv3,256bits,AES256-SHA) by wingspan with esmtp; Wed, 06 Aug 2008 14:50:26 -0400 id 00056453.4899F273.00016122 Date: Wed, 6 Aug 2008 14:50:31 -0400 From: Bill Moran To: d@delphij.net Message-Id: <20080806145031.9c94326a.wmoran@collaborativefusion.com> In-Reply-To: <4899F1AB.8080409@delphij.net> References: <4899F1AB.8080409@delphij.net> Organization: Collaborative Fusion X-Mailer: Sylpheed 2.5.0 (GTK+ 2.12.11; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: freebsd-net@freebsd.org, Xin LI , Quake Lee Subject: Re: Routing: local link vs VPN provided route X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Aug 2008 19:00:42 -0000 In response to Xin LI : > > We have recently working on an OpenVPN scenario and we have found that > when there is a locally linked network, the route provided by OpenVPN > would not work: > > - - Local network uses 192.168.1.0/24 network (thus we have a flags 'UC' > route) > > - - Upon connection, the VPN would provide a route to 192.168.1.0/24 > through the tun0 device. > > It seems, however, that the packets would just go to local network. Is > it possible to get packets to non-conflicting IP addresses (i.e. only > exist in either local network, or remote VPN'ed network) to go through > the tun0 device? Any hack you would do to make this work is going to be unreliable at best. Renumber your network so that routing can work as designed. -- Bill Moran Collaborative Fusion Inc. http://people.collaborativefusion.com/~wmoran/ wmoran@collaborativefusion.com Phone: 412-422-3463x4023