Technical data

4. Packages
OPENVPN_x_ROUTE_N Default: OPENVPN_x_ROUTE_N=”
This setting is only valid if OPENVPN_x_TYPE (Page 165) is set to ’tunnel’ for this Open-
VPN connection.
Routes are being set automatically by OpenVPN when starting up. Up to 50 nets
can be routed over a single OpenVPN connection. For every net to be routed a valid
OPENVPN_x_ROUTE_x entry must be created.
Please note that the packet filter rules necessary have to be set man-
ually in OPENVPN_PF_FORWARD_x OPENVPN_PF_INPUT_x res. OPENVPN_PF6_FORWARD_x
OPENVPN_PF6_INPUT_x. OpenVPN only allows ICMP over a VPN connection and de-
nies all other data traffic. Details can be found at OPENVPN_x_PF_INPUT_N (Page 175)
and OPENVPN_x_PF_FORWARD_N (Page 176) res. at OPENVPN_x_PF6_INPUT_N (Page 176) and
OPENVPN_x_PF6_FORWARD_N (Page 176).
OPENVPN_x_ROUTE_x Default: OPENVPN_x_ROUTE_x=”
Specify the nets to be reached over the OpenVPN remote station here. If on the remote
side i.e. the nets 192.168.33.0/24 and 172.18.0.0/16 can be reached and should be accessed
through the OpenVPN tunnel both of them have to be entered under OPENVPN_x_ROUTE_x.
Host routes (/32) may be set here as well.
If the default route should be reached through an OpenVPN tunnel specifiy 0.0.0.0/0
res. ::/0 for IPv6 and an optional flag as routes here. For IPv6 routes OPT_IPv6
has to be activated, local and remote IPv6 addresses for the tunnel have to be set and
OPENVPN_x_IPV6 must be ’yes’. OpenVPN has several alternative ways to set a
default route which can be chosen by a flag. Each method has its own advantages and
disadvantages. At the moment the following flags are supported:
local The local flag should be chosen if the OpenVPN remote station is located in a subnet
that can be reached directly by the fli4l router. This may be the case for example
for an OPENVPN default route over WLAN.
def1 With this flag two new routes 0.0.0.0/1 and 128.0.0.0/1 will be defined in addition
to a host route to the OpenVPN remote station. This routes act as default routes
for the complete (encrypted) traffic to the OpenVPN remote station (which can be
reached over the host route).
If omitting the optional flag OpenVPN will choose the method of setting default routes.
Methods will be picked by the OpenVPN version. At the moment local is the default
advised.
OPENVPN_1_ROUTE_N='3'
OPENVPN_1_ROUTE_1='192.168.33.0/24'
OPENVPN_1_ROUTE_2='172.18.0.0/16'
OPENVPN_1_ROUTE_3='2001:db8:/32'
OpenVPN - Delegation Of DNS and Reverse-DNS
OPENVPN_x_DOMAIN Default: OPENVPN_x_DOMAIN=”
This parameter sets the remote domain. The variable can hold multiple domains which
have to be separated by spaces then. If only this parameter is set (without mentioning of
168