helloabout the need of tap, it seems that DHCP relay requests don't work well with VPN, tap is the way if you want your dhcp broadcast to pass from the distant network to the dhcp server network. If someone has a tun vpn active with dhcp relay working, let me know, i will continue to try to make it work.
How did you verify it? You set a DHCP relay with the IP of DHCP in remote network and this has to be tunneled via VPN. I'm not sure why this shouldn't work?
What part of the linked tutorial is unclear?
10:55:49.808611 IP 0.0.0.0.68 > 255.255.255.255.67: UDP, length 30010:55:53.808592 IP 0.0.0.0.68 > 255.255.255.255.67: UDP, length 30010:56:02.808568 IP 0.0.0.0.68 > 255.255.255.255.67: UDP, length 30010:56:10.808539 IP 0.0.0.0.68 > 255.255.255.255.67: UDP, length 30010:56:14.808534 IP 0.0.0.0.68 > 255.255.255.255.67: UDP, length 300
11:28:36.391142 IP 128.42.66.111 > 224.0.0.18: VRRPv2, Advertisement, vrid 11, prio 100, authtype none, intvl 1s, length 2011:28:37.232701 ARP, Request who-has 128.42.66.160 (ff:ff:ff:ff:ff:ff) tell 0.0.0.0, length 4611:28:37.391080 IP 128.42.66.111 > 224.0.0.18: VRRPv2, Advertisement, vrid 11, prio 100, authtype none, intvl 1s, length 2011:28:38.109487 ARP, Request who-has 128.42.66.1 (ff:ff:ff:ff:ff:ff) tell 128.42.66.7, length 4611:28:38.391132 IP 128.42.66.111 > 224.0.0.18: VRRPv2, Advertisement, vrid 11, prio 100, authtype none, intvl 1s, length 20
14:48:31.338352 IP (tos 0x0, ttl 64, id 46583, offset 0, flags [none], proto ICMP (1), length 80) 128.42.66.6 > 128.42.66.7: ICMP echo request, id 19786, seq 35854, length 6014:48:31.339646 IP (tos 0x0, ttl 99, id 46583, offset 0, flags [none], proto ICMP (1), length 80) 128.42.66.7 > 128.42.66.6: ICMP echo reply, id 19786, seq 35854, length 60
BridgeVOIP1 Apr 25 14:49:51 128.42.66.7:67 255.255.255.255:68 udp let out anything from firewall host itself
QuoteWhat part of the linked tutorial is unclear?About the post in the how-to section about tap, at the beginning it is written that "this works for peer-to-peer mode as well" So in that case, I have to do the same bridge on the distant server no ? And the mode server is useless ?
NB: not a VLAN it does not work AFAIK