Hi, Thanks for the suggestions on this. Turns out the hosts were already set to rp_filter=1 I tried it with rp_filter=0 and it still requires the odd manual route via openvpn. The odd thing is it isn't needed on all hosts or for all networks. Basically I have to see what isn't accessible then add the relevant routes.
I haven't tried --redirect-gateway yet. -Ian Brooks On Friday 22 August 2014 15:47:18 Joe Patterson wrote: > Just out of curiosity, if I'm reading this correctly, if you use loose RPF > on a box, and also use the openvpn's --redirect-gateway def1 (which sets > two /1 routes), that would basically be equivalent to turning off RPF? > > -Joe > > > On Fri, Aug 22, 2014 at 1:34 PM, Josh Cepek <[email protected]> wrote: > > > Simon Deziel wrote: > > > > > On 08/21/2014 12:52 PM, Gert Doering wrote: > > >> Hi, > > >> > > >> On Thu, Aug 21, 2014 at 05:22:28PM +0100, Ian Brooks wrote: > > >>> I can see the traffic leaving the vm, hitting the internal gateway for > > >>> the bridge, hit the correct tunnel to the destination server and arrive > > >>> on tun0 on the destination server, but for some reason the packets > > arent > > >>> then passed to the internal bridge network, > > >> > > >> Sounds like linux' rp_filter is biting you "if the packet is not > > supposed > > >> to go there in the forward way, do not accept it on incoming". > > >> > > >> Look in "sysctl -a" for "rp_filter", set it to "0" for the relevant tun > > >> interfaces. > > > > > > Disabling rp_filter completely should do it but I'd just want to add > > > that "recent" linux version also allow loose mode rp filtering that > > > seems all indicated for asymmetric routing like this case. > > > > There's another benefit to using loose mode as well because the kernel > > takes > > the *largest* value between the interface-specific and 'all' values. While > > the kernel default is 0, many distros set net.ipv4.conf.all.rp_filter=1 in > > startup scripts. > > > > Using 2 on the interface allows this to be overridden without turning rp > > path protection off completely for all other interfaces. > > > > -- > > Josh > > > > > > > > ------------------------------------------------------------------------------ > > Slashdot TV. > > Video for Nerds. Stuff that matters. > > http://tv.slashdot.org/ > > _______________________________________________ > > Openvpn-users mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/openvpn-users > > ------------------------------------------------------------------------------ Slashdot TV. Video for Nerds. Stuff that matters. http://tv.slashdot.org/ _______________________________________________ Openvpn-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-users
