R7000> OpenVPN client and hosting servers

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
manthis
DD-WRT Novice


Joined: 11 Oct 2015
Posts: 9

PostPosted: Sun Oct 11, 2015 18:47    Post subject: R7000> OpenVPN client and hosting servers Reply with quote
Hello,

I just setup my brand new R7000 with ddwrt 24 and everything is running smooth except for one thing. I can't reach the server I'm hosting when openvpn client is on and I can't figure out why. When openvpn client is off my forwarding rules for port 80 and 443 works fine. But as soon as I enable openvpn client I can't reach my web server from outside anymore. Knowing my knownledge about iptables I'm sure there is something I miss but what?

Does someone have a clue about the situation?

Regards


Last edited by manthis on Fri Oct 16, 2015 12:50; edited 1 time in total
Sponsor
Paint
DD-WRT User


Joined: 22 Jun 2015
Posts: 135

PostPosted: Sun Oct 11, 2015 19:27    Post subject: Reply with quote
Even though this should be theoretically possible, the arm processor would seriously limit your throughput on both sides, even on the R8000. I would recommend using a raspberry pi 2, or equivalent devices to setup this sort of setup.
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Wed Oct 14, 2015 8:46    Post subject: Reply with quote
@Paint: It will be even slower on RPI2 as the network interface is connected by a slow USB.

@manthis: I suspect the the inbound forwarding is working, but the reply is routed through the VPN because the default route 0.0.0.0 is altered when the VPN connects.

Route the replay packets back out on the wan interface.

http://www.dd-wrt.com/wiki/index.php/Access_To_Modem_Configuration
http://www.dd-wrt.com/wiki/index.php/Policy_Based_Routing

Use a Policy Based routing as the Destination Address is not known as in the Modem Configuration Case.
Test on the lan ip address you have forwarded to and port 80 and 443.
manthis
DD-WRT Novice


Joined: 11 Oct 2015
Posts: 9

PostPosted: Thu Oct 15, 2015 20:36    Post subject: Reply with quote
Per Yngve Berg wrote:
@Paint: It will be even slower on RPI2 as the network interface is connected by a slow USB.

@manthis: I suspect the the inbound forwarding is working, but the reply is routed through the VPN because the default route 0.0.0.0 is altered when the VPN connects.

Route the replay packets back out on the wan interface.

http://www.dd-wrt.com/wiki/index.php/Access_To_Modem_Configuration
http://www.dd-wrt.com/wiki/index.php/Policy_Based_Routing

Use a Policy Based routing as the Destination Address is not known as in the Modem Configuration Case.
Test on the lan ip address you have forwarded to and port 80 and 443.


I suspected the same but had no idea how to fix the problem. Unfortunately I guess your links are way above my knowledge since I have no idea what to start with and actually do Sad

I just would like a specific machine trafic not to be routed through the VPN interface but by the regular WAN interface. Could someone with enough knowledge help me to do that?
manthis
DD-WRT Novice


Joined: 11 Oct 2015
Posts: 9

PostPosted: Fri Oct 16, 2015 13:38    Post subject: Reply with quote
Ok what I did is enable policy based routing for all my dhcp clients (192.168.1.224/27) in openvpn client configuration. So now my server is reaching wan with my regular ip address and all my dhcp clients on network 192.168.1.224/27 are goint out through my VPN.

I could have supposed I would be able to reach my server easily from outside now, but it's still not working. Does anyone have a clue on how to solve my problem?
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Sun Oct 18, 2015 9:02    Post subject: Reply with quote
Have you set up Port Forward in NAT at the WAN Interface?
slidermike
DD-WRT Guru


Joined: 11 Nov 2013
Posts: 1487
Location: USA

PostPosted: Sun Oct 18, 2015 11:55    Post subject: Reply with quote
I don't know if your interested but the XVortex asusmerlin port for the R7000 is supposed to have a pretty decent VPN solution implemented.

If your amenable to trying it just head on over and get it.
http://www.linksysinfo.org/index.php?threads/asuswrt-merlin-on-netgear-r7000.71108/

_________________
Router currently owned:
Netgear R7800 - Router
Netgear R7000 - AP mode

R7000 specific Tips/Tricks.
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=264152
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum