WAN / Internet -----------------------------------+ : | : Netz: 192.168.32.0/24 | : | .-----+-----. Gateway IP: 192.168.32.2 | | Gateway | VM Ware Workstaion | '-----+-----' | | | Open VPN | | Netz: 10.11.11.0/24 | | IP Lokal: 10.11.11.1 | WAN | | IP 192.168.32.128 | | | .-----+------. | | OPNsense +--------------------------------------+ '-----+------' | | | | +------------------------------------------------+ | | | LAN 1 | LAN2 | Netzadresse: | Netzadresse: | 192.168.1.0/24 | 192.168.2.0/24 | IP GW: 192.168.1.1 | IP GW: 192.168.2.1 | | .-----+------. .-----+------. | LAN-Switch | | LAN-Switch | '-----+------' '-----+------' | | | | ...-----+------... ...-----+------... 192.168.1.100... Clients Server etc... 192.168.2.100...
WAN / Internet -----------------------------------+ : | : Netz: 192.168.32.0/24 | : | .-----+-----. Gateway IP: 192.168.32.2 | | Gateway | VM Ware Workstaion | '-----+-----' | | | Open VPN | | Netz: 10.11.11.0/24 | | IP Lokal: 10.11.11.2 | WAN | | IP 192.168.32.130 | | | .-----+------. | | OPNsense +--------------------------------------+ '-----+------' | | | | +------------------------------------------------+ | | | LAN 1 | LAN2 | Netzadresse: | Netzadresse: | 192.168.3.0/24 | 192.168.4.0/24 | IP GW: 192.168.3.1 | IP GW: 192.168.4.1 | | .-----+------. .-----+------. | LAN-Switch | | LAN-Switch | '-----+------' '-----+------' | | | | ...-----+------... ...-----+------... 192.168.3.100... Clients Server etc... 192.168.4.100...
Proto Destination Gateway Flags Use MTU Netif Netif (name) Expireipv4 default 192.168.32.2 UGS 4415 1500 em0 wan ipv4 10.11.11.0/24 10.11.11.2 UGS 0 1500 ovpns1 ipv4 10.11.11.1 link#8 UHS 0 16384 lo0 ipv4 10.11.11.2 link#8 UH 0 1500 ovpns1 ipv4 127.0.0.1 link#4 UH 15158 16384 lo0 ipv4 192.168.1.0/24 link#3 U 131364 1500 em2 LAN1 ipv4 192.168.1.1 link#3 UHS 2 16384 lo0 ipv4 192.168.2.0/24 link#2 U 0 1500 em1 LAN2 ipv4 192.168.2.1 link#2 UHS 0 16384 lo0 ipv4 192.168.3.0/24 10.11.11.2 UGS 0 1500 ovpns1 ipv4 192.168.4.0/24 10.11.11.2 UGS 0 1500 ovpns1 ipv4 192.168.32.0/24 link#1 U 538 1500 em0 wan ipv4 192.168.32.2 00:0c:29:8c:10:0b UHS 4718 1500 em0 wan ipv4 192.168.32.128 link#1 UHS 0 16384 lo0 ipv6 ::1 link#4 UH 148 16384 lo0 ipv6 fe80::%em0/64 link#1 U 0 1500 em0 wan ipv6 fe80::20c:29ff:fe8c:100b%em0 link#1 UHS 0 16384 lo0 ipv6 fe80::%em1/64 link#2 U 0 1500 em1 LAN2 ipv6 fe80::20c:29ff:fe8c:1029%em1 link#2 UHS 0 16384 lo0 ipv6 fe80::%em2/64 link#3 U 6 1500 em2 LAN1 ipv6 fe80::20c:29ff:fe8c:1033%em2 link#3 UHS 0 16384 lo0 ipv6 fe80::%lo0/64 link#4 U 0 16384 lo0 ipv6 fe80::1%lo0 link#4 UHS 0 16384 lo0 ipv6 fe80::20c:29ff:fe8c:100b%ovpns1 link#8 UHS 0 16384 lo0 Showing 1 to 24 of 24 entries
Proto Destination Gateway Flags Use MTU Netif Netif (name) Expireipv4 default 192.168.32.2 UGS 4020 1500 em0 wan ipv4 10.11.11.0/24 10.11.11.1 UGS 0 1500 ovpnc1 ipv4 10.11.11.1 link#8 UH 0 1500 ovpnc1 ipv4 10.11.11.2 link#8 UHS 0 16384 lo0 ipv4 127.0.0.1 link#4 UH 21238 16384 lo0 ipv4 192.168.1.0/24 10.11.11.1 UGS 0 1500 ovpnc1 ipv4 192.168.2.0/24 10.11.11.1 UGS 0 1500 ovpnc1 ipv4 192.168.3.0/24 link#3 U 95169 1500 em2 LAN1 ipv4 192.168.3.1 link#3 UHS 2 16384 lo0 ipv4 192.168.4.0/24 link#2 U 0 1500 em1 LAN2 ipv4 192.168.4.1 link#2 UHS 0 16384 lo0 ipv4 192.168.32.0/24 link#1 U 419 1500 em0 wan ipv4 192.168.32.2 00:50:56:34:73:5d UHS 4056 1500 em0 wan ipv4 192.168.32.130 link#1 UHS 0 16384 lo0 ipv6 ::1 link#4 UH 148 16384 lo0 ipv6 fe80::%em0/64 link#1 U 0 1500 em0 wan ipv6 fe80::250:56ff:fe34:735d%em0 link#1 UHS 0 16384 lo0 ipv6 fe80::%em1/64 link#2 U 0 1500 em1 LAN2 ipv6 fe80::250:56ff:fe3a:a97b%em1 link#2 UHS 0 16384 lo0 ipv6 fe80::%em2/64 link#3 U 6 1500 em2 LAN1 ipv6 fe80::250:56ff:fe31:a7c2%em2 link#3 UHS 0 16384 lo0 ipv6 fe80::%lo0/64 link#4 U 0 16384 lo0 ipv6 fe80::1%lo0 link#4 UHS 0 16384 lo0 ipv6 fe80::%ovpnc1/64 link#8 U 0 1500 ovpnc1 ipv6 fe80::250:56ff:fe34:735d%ovpnc1 link#8 UHS 0 16384 lo0 Showing 1 to 25 of 25 entries
root@OPNsense1:/var/etc/openvpn # less server1.confdev ovpns1verb 5dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_server1.pidscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher AES-256-CBCauth SHA512up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal 192.168.32.128client-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"tls-serverserver 10.11.11.0 255.255.255.0client-config-dir /var/etc/openvpn-csc/1ifconfig 10.11.11.1 10.11.11.2tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'OPNsense1' 1"lport 1194management /var/etc/openvpn/server1.sock unixpush "route 192.168.1.0 255.255.255.0"push "route 192.168.2.0 255.255.255.0"route 192.168.3.0 255.255.255.0route 192.168.4.0 255.255.255.0ca /var/etc/openvpn/server1.cacert /var/etc/openvpn/server1.certkey /var/etc/openvpn/server1.keydh /usr/local/etc/dh-parameters.4096.samplecrl-verify /var/etc/openvpn/server1.crl-verifytls-auth /var/etc/openvpn/server1.tls-auth 0comp-lzo notopology subnetsndbuf 524288rcvbuf 524288auth-nocache#client-connect /etc/openvpn/scripts/Connection-Log.sh#client-disconnect /etc/openvpn/scripts/Connection-Log.shscript-security 2#persist-key#persist-tunserver1.conf (END)
root@OPNsense2:/var/etc/openvpn # less client1.confdev ovpnc1verb 5dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_client1.pidscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher AES-256-CBCauth SHA512up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal 192.168.32.130tls-clientclientlport 0management /var/etc/openvpn/client1.sock unixremote 192.168.32.128 1194ifconfig 10.11.11.2 10.11.11.1route 192.168.1.0 255.255.255.0route 192.168.2.0 255.255.255.0ca /var/etc/openvpn/client1.cacert /var/etc/openvpn/client1.certkey /var/etc/openvpn/client1.keytls-auth /var/etc/openvpn/client1.tls-auth 1comp-lzo noroute-nopullresolv-retry infinitesndbuf 524288rcvbuf 524288auth-nocacheclient1.conf (END)
LAN1:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * LAN1 net * * * * * Default allow LAN to any rule IPv6 * LAN1 net * * * * * Default allow LAN IPv6 to any ruleLAN2:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * LAN2 net * * * * * Default allow LAN to any rule IPv6 * LAN2 net * * * * * Default allow LAN IPv6 to any ruleOpenVPN:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * * * * * * * Default allow to any rule WAN1:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * * * * * * * all in (Testzwecke) IPv4 TCP/UDP * * WAN addr 1194 * * OpenVPN
LAN1:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * LAN1 net * * * * * Default allow LAN to any rule IPv6 * LAN1 net * * * * * Default allow LAN IPv6 to any ruleLAN2:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * LAN2 net * * * * * Default allow LAN to any rule IPv6 * LAN2 net * * * * * Default allow LAN IPv6 to any ruleOpenVPN:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * * * * * * * Default allow to any rule WAN1:Protocol Source Port Destination Port Gateway Schedule Description IPv4 * * * * * * * all in (Testzwecke)
Proto Destination Gateway Flags Use MTU Netif Netif (name) Expireipv4 default 192.168.32.2 UGS 8010 1500 em0 wan ipv4 10.11.11.1 link#8 UHS 0 16384 lo0 ipv4 10.11.11.2 link#8 UH 0 1500 ovpns1 ipv4 127.0.0.1 link#4 UH 34394 16384 lo0 ipv4 192.168.1.0/24 link#3 U 154312 1500 em2 LAN1 ipv4 192.168.1.1 link#3 UHS 2 16384 lo0 ipv4 192.168.2.0/24 link#2 U 0 1500 em1 LAN2 ipv4 192.168.2.1 link#2 UHS 0 16384 lo0 ipv4 192.168.3.0/24 10.11.11.2 UGS 0 1500 ovpns1 ipv4 192.168.4.0/24 10.11.11.2 UGS 0 1500 ovpns1 ipv4 192.168.32.0/24 link#1 U 96846 1500 em0 wan ipv4 192.168.32.2 00:0c:29:8c:10:0b UHS 56467 1500 em0 wan ipv4 192.168.32.128 link#1 UHS 0 16384 lo0 ipv6 ::1 link#4 UH 148 16384 lo0 ipv6 fe80::%em0/64 link#1 U 0 1500 em0 wan ipv6 fe80::20c:29ff:fe8c:100b%em0 link#1 UHS 0 16384 lo0 ipv6 fe80::%em1/64 link#2 U 0 1500 em1 LAN2 ipv6 fe80::20c:29ff:fe8c:1029%em1 link#2 UHS 0 16384 lo0 ipv6 fe80::%em2/64 link#3 U 6 1500 em2 LAN1 ipv6 fe80::20c:29ff:fe8c:1033%em2 link#3 UHS 0 16384 lo0 ipv6 fe80::%lo0/64 link#4 U 0 16384 lo0 ipv6 fe80::1%lo0 link#4 UHS 0 16384 lo0 ipv6 fe80::20c:29ff:fe8c:100b%ovpns1 link#8 UHS 0 16384 lo0 Showing 1 to 23 of 23 entries
Proto Destination Gateway Flags Use MTU Netif Netif (name) Expireipv4 default 192.168.32.2 UGS 6612 1500 em0 wan ipv4 10.11.11.1 link#8 UH 0 1500 ovpnc1 ipv4 10.11.11.2 link#8 UHS 0 16384 lo0 ipv4 127.0.0.1 link#4 UH 42188 16384 lo0 ipv4 192.168.1.0/24 10.11.11.1 UGS 0 1500 ovpnc1 ipv4 192.168.2.0/24 10.11.11.1 UGS 0 1500 ovpnc1 ipv4 192.168.3.0/24 link#3 U 109166 1500 em2 LAN1 ipv4 192.168.3.1 link#3 UHS 2 16384 lo0 ipv4 192.168.4.0/24 link#2 U 0 1500 em1 LAN2 ipv4 192.168.4.1 link#2 UHS 0 16384 lo0 ipv4 192.168.32.0/24 link#1 U 22021 1500 em0 wan ipv4 192.168.32.2 00:50:56:34:73:5d UHS 6651 1500 em0 wan ipv4 192.168.32.130 link#1 UHS 0 16384 lo0 ipv6 ::1 link#4 UH 148 16384 lo0 ipv6 fe80::%em0/64 link#1 U 0 1500 em0 wan ipv6 fe80::250:56ff:fe34:735d%em0 link#1 UHS 0 16384 lo0 ipv6 fe80::%em1/64 link#2 U 0 1500 em1 LAN2 ipv6 fe80::250:56ff:fe3a:a97b%em1 link#2 UHS 0 16384 lo0 ipv6 fe80::%em2/64 link#3 U 6 1500 em2 LAN1 ipv6 fe80::250:56ff:fe31:a7c2%em2 link#3 UHS 0 16384 lo0 ipv6 fe80::%lo0/64 link#4 U 0 16384 lo0 ipv6 fe80::1%lo0 link#4 UHS 0 16384 lo0 ipv6 fe80::250:56ff:fe34:735d%ovpnc1 link#8 UHS 0 16384 lo0 Showing 1 to 23 of 23 entries
root@OPNsense1:/var/etc/openvpn # less server1.confdev ovpns1verb 5dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_server1.pidscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher AES-256-CBCauth SHA512up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal 192.168.32.128ifconfig 10.11.11.1 10.11.11.2lport 1194management /var/etc/openvpn/server1.sock unixpush "route 192.168.1.0 255.255.255.0"push "route 192.168.2.0 255.255.255.0"route 192.168.3.0 255.255.255.0route 192.168.4.0 255.255.255.0secret /var/etc/openvpn/server1.secretcomp-lzo nosndbuf 524288rcvbuf 524288auth-nocache#client-connect /etc/openvpn/scripts/Connection-Log.sh#client-disconnect /etc/openvpn/scripts/Connection-Log.shscript-security 2#persist-key#persist-tunserver1.conf (END)
root@OPNsense2:/var/etc/openvpn # less client1.confdev ovpnc1verb 5dev-type tuntun-ipv6dev-node /dev/tun1writepid /var/run/openvpn_client1.pidscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher AES-256-CBCauth SHA512up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal 192.168.32.130lport 0management /var/etc/openvpn/client1.sock unixremote 192.168.32.128 1194ifconfig 10.11.11.2 10.11.11.1route 192.168.1.0 255.255.255.0route 192.168.2.0 255.255.255.0secret /var/etc/openvpn/client1.secretcomp-lzo noroute-nopullresolv-retry infinitesndbuf 524288rcvbuf 524288auth-nocacheclient1.conf (END)
Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: timers and/or timeouts modified Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: --ifconfig/up options modified Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: route-related options modified Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: peer-id set Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: adjusting link_mtu to 1625 Nov 5 13:42:12 OPNsense2 openvpn[8916]: OPTIONS IMPORT: data channel crypto options modified