DDWRT OpenVPN routed

Steelerz37

Senior member
Feb 15, 2003
693
0
0
I recently had to replace 1 of my dd-wrt openvpn routers and decided to take the opportunity to convert to public private keys. I previsouly had a static key VPN configured and working well for quite a while.

It looks to me like my certificates and pub/priv keys are all working just fine, as soon as I power on the DD-WRT OpenVPN server[server] the DD-WRT OpenVPN client[client1] connects and gets a private address, but I am not able to connect or ping any devices on the client1 lan.
So I think I think my problem is either in routing or the iptables firewall on either server or client1. My knowledge of iptables and routing is very minimal

I have been following the vpn guide at:
http://www.dd-wrt.com/wiki/index.php/VPN_%28the_easy_way)_v24+#Enough_NVRAM_storage_space.3F


I'll try to explain my configuration as best as possible:

Server:
Linksys WRT54G
LAN: 192.168.3.x
VPN Private Routing: 192.168.66.0

OpenVPN Server Config Script:
##################################################
push "route 192.168.3.0 255.255.255.0"
server 192.168.66.0 255.255.255.0

dev tun0
proto udp
keepalive 10 120
dh /tmp/openvpn/dh.pem
ca /tmp/openvpn/ca.crt
cert /tmp/openvpn/cert.pem
key /tmp/openvpn/key.pem

# Only use crl-verify if you are using the revoke list - otherwise leave it commented out
# crl-verify /tmp/openvpn/ca.crl

# management parameter allows DD-WRT\s OpenVPN Status web page to access the server\s management port
# port must be 5001 for scripts embedded in firmware to work
management localhost 5001
##################################################

IPTABLES:
iptables -I INPUT 1 -p udp --dport 1194 -j ACCEPT
iptables -I FORWARD 1 --source 192.168.66.0/24 -j ACCEPT
iptables -I FORWARD -i br0 -o tun0 -j ACCEPT
iptables -I FORWARD -i tun0 -o br0 -j ACCEPT


*****************************************************************
Client1
Linksys WRT54G
LAN: 192.168.2.x
VPN Private Routing: 192.168.66.0
IPTABLES:
NONE
 
Last edited:

Steelerz37

Senior member
Feb 15, 2003
693
0
0
I did some modifications to the openvpn server config file and think i am closer, here is the new config:
push "route 192.168.3.0 255.255.255.0"
push "route 192.168.2.0 255.255.255.0"
route 192.168.2.0 255.255.255.0
client-config-dir /tmp/openvpn/ccd
server 192.168.66.0 255.255.255.0

dev tun0
proto udp
keepalive 10 120
dh /tmp/openvpn/dh.pem
ca /tmp/openvpn/ca.crt
cert /tmp/openvpn/cert.pem
key /tmp/openvpn/key.pem

# Only use crl-verify if you are using the revoke list
# crl-verify /tmp/openvpn/ca.crl

# management parameter allows DD-WRT's OpenVPN Status web
# port must be 5001 for scripts embedded in firmware to work
management localhost 5001


Now when I do a traceroute from 192.168.3.0 to 192.168.2.0 I see the route go over the 192.168.66.0 network, so I think I need to add the same iptables commands to the client as i am already running on the server.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |