dev tunport 1194proto udpmode servertopology subnetserver 10.8.1.0 255.255.255.0keepalive 10 60ifconfig-pool-persist ipp.txtfloatpush "route 10.8.0.0 255.255.255.0"push "route 10.8.2.0 255.255.255.0"push "route 10.8.3.0 255.255.255.0"push "route 10.8.4.0 255.255.255.0"push "route 10.8.5.0 255.255.255.0"push "route 10.8.6.0 255.255.255.0"push "route 10.8.7.0 255.255.255.0"push "route 10.8.8.0 255.255.255.0"push "route 10.8.9.0 255.255.255.0"push "route 10.8.10.0 255.255.255.0"push "route 10.8.11.0 255.255.255.0"push "route 10.8.12.0 255.255.255.0"push "dhcp-option DNS 10.8.0.10"client-to-clientca /etc/openvpn/easy-rsa2/keys/ca.crtcert /etc/openvpn/easy-rsa2/keys/server.crtkey /etc/openvpn/easy-rsa2/keys/server.keydh /etc/openvpn/easy-rsa2/keys/dh2048.pemcomp-lzo yes
...du hast es jetzt geschafft, dreimal über deine Konfiguration zu schreiben, aber weder die Client config noch NAT noch Firewallregeln auf der opnsense zu zeigen (und NAT und Firewallregeln auf dem Server auch nicht, oder?). Reife Leistung! ;-)
dev ovpnc2verb 3dev-type tuntun-ipv6dev-node /dev/tun2writepid /var/run/openvpn_client2.pid#user nobody#group nobodyscript-security 3daemonkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udpcipher BF-CBCauth SHA1up /usr/local/sbin/ovpn-linkupdown /usr/local/sbin/ovpn-linkdownlocal 84.153.213.63tls-clientclientlport 0management /var/etc/openvpn/client2.sock unixremote lxc.plt-dev.de 1194ca /var/etc/openvpn/client2.cacert /var/etc/openvpn/client2.certkey /var/etc/openvpn/client2.keycomp-lzo adaptive
ipv4 default 62.155.243.138 UGS 192448 1492 pppoe0 wan ipv4 10.0.0.0/24 link#1 U 9705463 1500 re0 LAN ipv4 10.0.0.1 link#1 UHS 0 16384 lo0 ipv4 10.1.0.0/24 link#6 U 0 1500 ue0 MODEM ipv4 10.1.0.1 link#6 UHS 0 16384 lo0 ipv4 10.2.0.0/24 link#8 U 281437 1500 re0_vlan2 MEDIA ipv4 10.2.0.1 link#8 UHS 0 16384 lo0 ipv4 10.3.0.0/24 10.3.0.2 UGS 0 1500 ovpns1 ipv4 10.3.0.1 link#7 UHS 0 16384 lo0 ipv4 10.3.0.2 link#7 UH 21718 1500 ovpns1 ipv4 10.8.0.0/24 10.8.1.1 UGS 4 1500 ovpnc2 DEV ipv4 10.8.1.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.1.1 link#10 UH 0 1500 ovpnc2 DEV ipv4 10.8.1.12 link#10 UHS 0 16384 lo0 ipv4 10.8.2.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.3.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.4.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.5.0/24 10.8.1.1 UGS 2 1500 ovpnc2 DEV ipv4 10.8.6.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.7.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.8.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.9.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.10.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.11.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 10.8.12.0/24 10.8.1.1 UGS 0 1500 ovpnc2 DEV ipv4 62.155.243.138 link#9 UH 0 1492 pppoe0 wan ipv4 84.153.213.63 link#9 UHS 0 16384 lo0 ipv4 127.0.0.1 link#3 UH 14637 16384 lo0
Kernel IP routing tableDestination Gateway Genmask Flags MSS Window irtt Ifacedefault 10.8.0.1 0.0.0.0 UG 0 0 0 eth010.8.0.0 * 255.255.255.0 U 0 0 0 eth010.8.1.0 * 255.255.255.0 U 0 0 0 tun0
dev tunport 1194proto udpmode servertopology subnetserver 10.8.1.0 255.255.255.0keepalive 10 60ifconfig-pool-persist ipp.txtfloat# Wird benötigt, damit OpenVPN eine Route zu diesem Netz bereitstelltroute 10.0.0.0 255.255.255.0push "route 10.8.0.0 255.255.255.0"push "route 10.8.2.0 255.255.255.0"push "route 10.8.3.0 255.255.255.0"push "route 10.8.4.0 255.255.255.0"push "route 10.8.5.0 255.255.255.0"push "route 10.8.6.0 255.255.255.0"push "route 10.8.7.0 255.255.255.0"push "route 10.8.8.0 255.255.255.0"push "route 10.8.9.0 255.255.255.0"push "route 10.8.10.0 255.255.255.0"push "route 10.8.11.0 255.255.255.0"push "route 10.8.12.0 255.255.255.0"push "dhcp-option DNS 10.8.0.10"client-to-clientca /etc/openvpn/easy-rsa2/keys/ca.crtcert /etc/openvpn/easy-rsa2/keys/server.crtkey /etc/openvpn/easy-rsa2/keys/server.keydh /etc/openvpn/easy-rsa2/keys/dh2048.pemcomp-lzo yes# Wird benötigt um je nach connectetem Client Netzwerke zu pushenclient-config-dir ccd
iroute 10.0.0.0 255.255.255.0