клиент цепляется к серверу и дальше никуда, нужно пробросить маршрут в 40 подсеть.
система
debian 9
allow-hotplug ens18
iface ens18 inet static
address 192.168.0.35
netmask 255.255.255.0
gateway 192.168.0.1
# dns-* options are implemented by the resolvconf package, if installed
dns-nameservers 192.168.0.1
iface ens18:0 inet static
address 192.168.40.35
netmask 255.255.255.0
auto ens18:0
cat /etc/openvpn/server.conf
local 192.168.0.35
port 1194
proto udp
dev tun
ca ca.crt
cert server.crt
key server.key # This file should be kept secret
dh dh2048.pem
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "route 192.168.40.0 255.255.255.0"
client-config-dir ccd
client-to-client
keepalive 10 120
tls-auth ta.key 0 # This file is secret
cipher AES-256-CBC
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 9
explicit-exit-notify 1
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o ens18:0 -j MASQUERADE
sysctl -p
net.ipv4.ip_forward = 1
cat /etc/openvpn/ccd/client1
на клиенте
client
dev tun
proto udp
remote XX.XX.XX.XX 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca "C:\\Program Files\\OpenVPN\\config\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\config\\client1.crt"
key "C:\\Program Files\\OpenVPN\\config\\client1.key"
tls-auth "C:\\Program Files\\OpenVPN\\config\\ta.key" 1
auth-nocache
verb 9
cipher AES-256-CBC
mute 20
comp-lzo
Лог на клиенте
Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {E3CE95EA-2B8E-4A68-AD1B-89B9C5FE84C5} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Tue Mar 13 12:44:02 2018 Successful ARP Flush on interface [12] {E3CE95EA-2B8E-4A68-AD1B-89B9C5FE84C5}
Tue Mar 13 12:44:02 2018 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Tue Mar 13 12:44:02 2018 MANAGEMENT: >STATE:1520934242,ASSIGN_IP,,10.8.0.6,,,,
Tue Mar 13 12:44:07 2018 TEST ROUTES: 2/2 succeeded len=2 ret=1 a=0 u/d=up
Tue Mar 13 12:44:07 2018 MANAGEMENT: >STATE:1520934247,ADD_ROUTES,,,,,,
Tue Mar 13 12:44:07 2018 C:\Windows\system32\route.exe ADD 192.168.40.0 MASK 255.255.255.0 10.8.0.5
Tue Mar 13 12:44:07 2018 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Tue Mar 13 12:44:07 2018 Route addition via IPAPI succeeded [adaptive]
Tue Mar 13 12:44:07 2018 C:\Windows\system32\route.exe ADD 10.8.0.0 MASK 255.255.255.0 10.8.0.5
Tue Mar 13 12:44:07 2018 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Tue Mar 13 12:44:07 2018 Route addition via IPAPI succeeded [adaptive]
Tue Mar 13 12:44:07 2018 Initialization Sequence Completed