Server Mode: Remote Access (SSL/TLS + User Auth)Protocol: UDPDevice Mode: tunInterface: WANLocal port: 1194TLS Authentication: checkedCertificate Depth: One (Client+Server)IPv4 Tunnel Network: 10.0.8.0/24Redirect Gateway: checkedCompression: Enabled with Adaptive CompressionDisable IPv6: checkedDynamic IP: checkedAddress Pool: checkedTopology: checkedForce DNS cache update: checked
pass, IPv4 UDP, *, *, WAN address 1194, *, OpenVPN wizard
However, the clients cannot connect to the Internet through the vpn.
$ nslookup -q=soa google.com 8.8.8.8Server: 8.8.8.8Address: 8.8.8.8#53Non-authoritative answer:google.com origin = ns1.google.com mail addr = dns-admin.google.com serial = 187645724 refresh = 900 retry = 900 expire = 1800 minimum = 60Authoritative answers can be found from:
$ ip route get 8.8.8.88.8.8.8 via 10.0.8.1 dev tun0 src 10.0.8.2 cache
$ ip route show0.0.0.0/1 via 10.0.8.1 dev tun0 default via 10.41.yyy.yyy dev wlp3s0 proto static metric 600 10.0.8.0/24 dev tun0 proto kernel scope link src 10.0.8.2 10.41.0.0/18 dev wlp3s0 proto kernel scope link src 10.41.yyy.yyy metric 600 10.255.255.254 via 10.41.0.1 dev wlp3s0 proto dhcp metric 600 xxx.xxx.xxx.xxx via 10.41.0.1 dev wlp3s0 128.0.0.0/1 via 10.0.8.1 dev tun0 169.254.0.0/16 dev tun0 scope link metric 1000
pass IPV4 *, OpenVPN net, *, *, *, *
Verify Server CN Automatic-Use verify-x509-nameUse Random Local Port checked
pass, IPv4 *, OpenVPN net, *, *, *, *, OpenVPN wizard
$ nslookup google.com 8.8.8.8Server: 8.8.8.8Address: 8.8.8.8#53Non-authoritative answer:Name: google.comAddress: 216.58.214.110
$ nslookup google.comServer: 127.0.1.1Address: 127.0.1.1#53Non-authoritative answer:Name: google.comAddress: 216.58.214.78
Thu May 24 19:40:18 2018 us=366858 TUN WRITE [64]Thu May 24 19:40:18 2018 us=367395 UDPv4 READ [161] from [AF_INET]xxx.xxx.xxx.xxx:1194: P_DATA_V1 kid=0 DATA len=160Thu May 24 19:40:18 2018 us=367685 TUN WRITE [64]Thu May 24 19:40:18 2018 us=367881 TUN READ [1328]Thu May 24 19:40:18 2018 us=368478 UDPv4 WRITE [1425] to [AF_INET]xxx.xxx.xxx.xxx:1194: P_DATA_V1 kid=0 DATA len=1424Thu May 24 19:40:18 2018 us=368823 TUN READ [1328]Thu May 24 19:40:18 2018 us=369423 UDPv4 WRITE [1425] to [AF_INET]xxx.xxx.xxx.xxx:1194: P_DATA_V1 kid=0 DATA len=1424
1018 115.665848000 10.0.8.2 34.217.184.213 TCP 1328 [TCP Retransmission] 54801→443 [ACK] Seq=334 Ack=3033 Win=35584 Len=1276 TSval=499056 TSecr=12870319601023 119.121651000 10.0.8.2 34.217.184.213 TCP 1328 [TCP Out-Of-Order] 54802→443 [ACK] Seq=334 Ack=3033 Win=35584 Len=1276 TSval=499920 TSecr=12870319981029 122.384418000 93.184.220.29 10.0.8.2 TCP 52 [TCP Keep-Alive ACK] 80→48290 [ACK] Seq=2365 Ack=1375 Win=148480 Len=0 TSval=1070943662 TSecr=4880921030 123.153667000 10.0.8.2 34.217.184.213 TCP 52 [TCP Keep-Alive] 54804→443 [ACK] Seq=1198 Ack=3189 Win=36608 Len=0 TSval=500928 TSecr=1287042247