OPNsense Forum

English Forums => General Discussion => Topic started by: TrueType on September 03, 2020, 10:55:47 PM

Title: OpenVPN-AS: Advanced options
Post by: TrueType on September 03, 2020, 10:55:47 PM
Hey,

I put the command "push "route 192.168.1.0 255.255.255.0"" in my "Advanced" options box in the OpenVPN Access Server in order to reach my clients from LAN and vice versa. But it says under the Advanced box that it is going to be removed in the future? (Full message below) Can I get the same result another (read better) way? :)

This option will be removed in the future due to being insecure by nature. In the mean time only full administrators are allowed to change this setting.

Title: Re: OpenVPN-AS: Advanced options
Post by: ManBat on January 20, 2022, 09:10:17 PM
Just giving this topic a nudge,

I have exactly the same issue, it looks like the IP V/4 local network box doesn't do what you want it to
Title: Re: OpenVPN-AS: Advanced options
Post by: mimugmail on January 21, 2022, 08:02:34 AM
Why shouldnt't routes get pushed? Can you show screenshots please
Title: Re: OpenVPN-AS: Advanced options
Post by: ManBat on January 21, 2022, 08:33:14 AM
Hey,

I don't know why they don't but: https://forum.opnsense.org/index.php?topic=26447.0

Explains what I've observed.

Plan today is to redo my tests and check the client route tables.

Cheers,
MMB
Title: Re: OpenVPN-AS: Advanced options
Post by: mimugmail on January 21, 2022, 12:54:12 PM
If you want to push routes and use "Remote Access XX" as server mode, dont forget to add client specific overrides for usernames, otherwise routes don't get pushed.
Title: Re: OpenVPN-AS: Advanced options
Post by: ManBat on January 21, 2022, 05:55:29 PM
ahhh, ok, the road warrior VPN setup configuration should reference this as my following the guide is probably pretty typical.

Title: Re: OpenVPN-AS: Advanced options
Post by: mimugmail on January 21, 2022, 07:47:49 PM
Roaswarriors usually dont have routed networks behind :)
But Docs always needs some love
Title: Re: OpenVPN-AS: Advanced options
Post by: ManBat on January 22, 2022, 08:14:29 AM
Well I dunno, I mean presumably the reason for using the VPN in the common case is to get to the network on the inside.