快速提问只是为了验证我不会精神错乱。如果使用设备模式“tap”并且我获得了功能齐全的连接,因为我可以毫无问题地从客户端 ping 到服务器。
但是,我想强制我的流量通过 VPN,无论如何都不会泄漏。我对此很困惑,但这不应该在server.ovpn
?
mode server
tls-server
...
dev tap
dev-node TAP1
ifconfig 192.168.0.1 255.255.255.0
ifconfig-pool 192.168.0.10 192.168.0.20
route-gateway 192.168.0.1
route 192.168.0.0 255.255.255.0 192.168.0.1
client-to-client
push "route 192.168.0.0 255.255.255.0 192.168.0.1"
push "route-gateway 192.168.0.1"
push "redirect-gateway def1"
Run Code Online (Sandbox Code Playgroud)
的client.ovpn
样子:
client
tls-client
dev tap
dev-node TAP1
...
pull
Run Code Online (Sandbox Code Playgroud)
连接建立,什么没有,客户端日志的输出是:
ROUTE default_gateway=<external IP gateway>
PUSH: Recieved control message: 'PUSH_REPLY,route 192.168.0.0 255.255.255.0 192.168.0.1,route-gateway...
Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.0.10/255.255.255.0 on interface ...
Successful ARP Flush
Added routes 139.. 127.. 192...
Run Code Online (Sandbox Code Playgroud)
除了检查时未设置默认网关外,一切似乎都很好 ipconfig /all
的输出route print
看起来像:
Destination Netmask Gateway
0.0.0.0 0.0.0.0 <external Gateway> <-- Wrong?
192.168.0.0 255.255.255.0 On-link
192.168.0.0 255.255.255.0 192.168.0.1
Run Code Online (Sandbox Code Playgroud)
路由表好像关闭了?
All appears to be fine except that a default gateway just isn't
set when checking
...
push "redirect-gateway def1"
Run Code Online (Sandbox Code Playgroud)
如果您使用该选项,则不会设置默认网关。相反,应该为0.0.0.0/1
和128.0.0.0/1
为您的 VPN添加两条路由。
归档时间: |
|
查看次数: |
41888 次 |
最近记录: |