Hi, On Tue, Jun 02, 2015 at 06:38:59PM +0800, Zesen Qian wrote: > Is using tap instead of tun my only choice? As I 've already seen > packets flowing out of the tun interface in the server end, the only > problem is that the packets is not forward to another interface.
Might be rp_filter getting in the way, if you routing is not set up symmetrically on the server side (outside OpenVPN). Hard to say without further details. And no, don't go to tap unless you fully understand why tun is not possible for you - there are a few scenarios (transparent bridging between networks to make IPX or multicast work, for example, or "AIX machines that do not have tun interfaces") but usually tun is the better choice. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025 g...@net.informatik.tu-muenchen.de
pgpA4qyKNcqwd.pgp
Description: PGP signature
------------------------------------------------------------------------------
_______________________________________________ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users