User`s manual
TC-6110 Linux User's Manual  Managing Communications 
3-29 
route add -net 192.168.2.0 netmask 255.255.255.0 dev br0 
#---------------------------------- end ----------------------------- 
7.  And then configure the bridge interface script in /etc/openvpn/bridge. 
#!/bin/bash 
# Create global variables 
# Define Bridge Interface 
br=“br0” 
# Define list of TAP interfaces to be bridged, 
# for example tap=“tap0 tap1 tap2”. 
tap=“tap0” 
# Define physical ethernet interface to be bridged 
# with TAP interface(s) above. 
eth=“eth1” 
eth_ip=“192.168.8.174” 
eth_netmask=“255.255.255.0” 
eth_broadcast=“192.168.8.255” 
#gw=“192.168.8.173” 
... 
8.  Start the bridge script file to configure the bridge interface. 
moxa@MOXA:~# /etc/openvpn/bridge restart 
9.  Start the OpenVPN peers that are on machine OpenVPN A and OpenVPN B with the following command: 
moxa@MOXA:~# openvpn --config /etc/openvpn/tap0-br.conf& 
If you see a line that looks like Peer Connection Initiated with 192.168.8.173:5000on each machine, 
then the connection the Ehternet bridge has been successfully established over UDP port 5000.   
10. Check the routing table on each VPN server by typing the command below: 
moxa@MOXA:~# route 
Destination   Gateway Genmsk      Flags  Metric  Ref Use Iface 
192.168.5.0   0.0.0.0 255.255.255.0 U    0   0 0   eth2 
192.168.4.0   0.0.0.0 255.255.255.0 U    0   0 0   br0 
192.168.3.0   0.0.0.0 255.255.255.0 U    0    0 0   eth0 
192.168.30.0  0.0.0.0 255.255.255.0  U    0   0 0   eth3 
192.168.8.0   0.0.0.0 255.255.255.0 U    0   0 0   br0 
Interface eth1 and device tap0 both connect to the bridging interface, and the virtual device tun sits on 
top of tap0. This ensures that all traffic coming to this bridge from internal networks connected to 
interface eth1 write to the TAP/TUN device that the OpenVPN program monitors. Once the OpenVPN 
program detects traffic on the virtual device, it sends the traffic to its peer. 
11.  To create an indirect connection to Host B from Host A, you need to add the following routing item: 
moxa@MOXA:~# route add –net 192.168.4.0 netmask 255.255.255.0 dev eth0 
To create an indirect connection to Host A from Host B, you need to add the following routing item: 
moxa@MOXA:~# route add –net 192.168.2.0 netmask 255.255.255.0 dev eth0 
Now ping Host B from Host A by typing:   
moxa@MOXA:~# ping 192.168.4.174 
A successful ping indicates that you have created a VPN system that only allows authorized users from 
one internal network to access users at the remote site. For this system, all data is transmitted by UDP 
packets on port 5000 between OpenVPN peers. 
12.  To shut down the VPN servers, use the killall command: 
moxa@MOXA:~# killall -TERM openvpn 










