Simultaneous OpenVPN Server and Client Possible?

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
dpw95
DD-WRT Novice


Joined: 21 Jul 2019
Posts: 22

PostPosted: Sun Jun 19, 2022 17:08    Post subject: Simultaneous OpenVPN Server and Client Possible? Reply with quote
I am able to have my router connect to my VPN provider.

I am also able to have my router act as a VPN server, where I can authenticate to it when away from home to access my local network resources.

However, I found that if my router is connected to my VPN provider, I am not able to connect to its own VPN server.

I came by the thread below which at the time had the same goal I have now, but it reads as though some of the posts are no longer displayed throughout it:

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=313188&sid=3bfb909d6f12debf6487685fa05a0899

Is the setup I am pursuing anything known to be possible with current builds? If anyone has pointers for resources that go over this, I'd greatly appreciate those leads.

My current firmware: DD-WRT v3.0-r48996 std (05/30/22)

Thank you all!
Sponsor
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9157

PostPosted: Sun Jun 19, 2022 17:25    Post subject: Reply with quote
Simultaneous OpenVPN client and server only becomes a problem if the target of remote access over the WAN is bound to the OpenVPN client. At that point, any attempt to reach the target device over the WAN (either the router itself, or WLAN/LAN devices) becomes problematic. The replies from the remote access over the WAN get routed back over the VPN, which is NOT allowed due to RPF (reverse-path filtering).

IOW, the router requires all traffic entering and leaving the local network to use the *same* network interface. You can't come in via the WAN and exit via the VPN, or vice-versa.

The most common way to get around the issue when it comes to remote access of the router and its various services, including the OpenVPN server, is to enable PBR (policy based routing), which by definition, removes the router itself from the OpenVPN client.

_________________
ddwrt-ovpn-split-basic.sh (UPDATED!) * ddwrt-ovpn-split-advanced.sh (UPDATED!) * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-remote-access.sh * ddwrt-ovpn-client-backup.sh * ddwrt-mount-usb-drives.sh * ddwrt-blacklist-domains.sh * ddwrt-wol-port-forward.sh * ddwrt-dns-monitor.sh (NEW!)
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1899

PostPosted: Sun Jun 19, 2022 18:27    Post subject: Reply with quote
That thread you linked is dated (and possibly irrelevant).
You might want to read the information linked here in this sticky:

OpenVPN guides and documentation

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12837
Location: Netherlands

PostPosted: Sun Jun 19, 2022 18:46    Post subject: Reply with quote
@dpw95 that link is outdated as @dale_gribble39 already said and I think it is missing the relevant information from @eibgrad (we had a melt down of some sorts where extremely relevant information was accidentally removed)

@eibgrad really said it all.

The OpenVPN server setup guide has a paragraph about running an OpenVPN Client and OpenVPN server on the same router.

Key words: Policy Based Routing (PBR)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum