OpenVPN and policy routing

Victor Sudakov vas at mpeks.tomsk.su
Thu Mar 30 03:22:27 UTC 2017


Dear Colleagues,

Anyone experienced with OpenVPN on FreeBSD?

What would be the best way to policy route a network into OpenVPN? A
routing decision must be based on the src IP address, not the dst IP
address.

Imagine an OpenVPN client with 3 interfaces: fxp0 is the outside
interface towards the OpenVPN server, fxp1 is for LAN1 and fxp2 for
LAN2.

 From LAN1, some private networks are reachable through OpenVPN
(tun0), this is done via the regular route commands (pulled from the
OpenVPN server).

 From LAN2, *everything* should be reachable only through OpenVPN.
Which is the best way to accomplish this?

-- 
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
AS43859


More information about the freebsd-net mailing list