Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 1 Aug 2009 13:32:59 +0200
From:      Stefan Bethke <stb@lassitu.de>
To:        Matthias Andree <matthias.andree@gmx.de>
Cc:        freebsd-ports@freebsd.org
Subject:   Re: recent change to ifconfig breaks OpenVPN?
Message-ID:  <654B1E65-BF46-4DD7-9DCE-97965875F1DE@lassitu.de>
In-Reply-To: <C1D6F367-1036-4225-8A4A-D1894510AA18@lassitu.de>
References:  <B4AA014B-2444-40AA-A3A3-417E4B89DF90@lassitu.de> <4A709126.5050102@elischer.org> <3A1518B9-2C8C-4F05-9195-82C6017E4902@lassitu.de> <op.uxusbswp1e62zd@merlin.emma.line.org> <BEE762CA-4282-4BA8-B92B-AFC7AAE3CA9A@lassitu.de> <ABCF4747-24D4-4435-952B-EA85A2AE999F@lassitu.de> <B583FBF374231F4A89607B4D08578A4304E22D95@bcs-mail03.internal.cacheflow.com> <4A721160.5080902@elischer.org> <20090730220658.M245@maildrop.int.zabbadoz.net> <op.uxwkqxxd1e62zd@merlin.emma.line.org> <B80ED984-7570-4C00-911C-7F47E25680D6@lassitu.de> <C1D6F367-1036-4225-8A4A-D1894510AA18@lassitu.de>

next in thread | previous in thread | raw e-mail | index | archive | help
Am 31.07.2009 um 18:58 schrieb Stefan Bethke:

> Am 31.07.2009 um 14:38 schrieb Stefan Bethke:
>
>> Here's a first draft at a patch for OpenVPN.  With this, the tun  
>> interface gets set to IFF_BROADCAST mode.  One small piece is still  
>> missing: OpenVPN tries to install a route for the subnet, but that  
>> fails because now ifconfig has already inserted that route.  I'll  
>> try to look into that a bit later on.  I also haven't tested the  
>> server side yet, or any other mode.
>
> The route for the subnet is pushed by the server (expanded from the  
> --server config option).  Although adding the route fails, the  
> connection process continues and the connection is working fine.   
> Making either the client ignore the pushed route or the server not  
> push the route would be rather intrusive, so I think leaving it at  
> this should be acceptable.
>
> Will continue testing...

I've tested the patch on -stable and -current, with --topology subnet  
and --topology net30, in client and server modes, and everything seems  
to be working fine.  From my point of view, this can be committed.

I will submit the patch to James Yonan and the openvpn-developers list  
for inclusion.


Stefan

-- 
Stefan Bethke <stb@lassitu.de>   Fon +49 151 14070811







Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?654B1E65-BF46-4DD7-9DCE-97965875F1DE>