Установил на даче роутер чтобы из дома иметь доступ к Ip-камерам (rtsp поток). Установил соединение между роутерами через OpenVpn туннель. Но доступ из одной сети в другую настроить не получается - пинги не проходят.
Домашняя сеть 192.168.1.0, роутер Asus RT-N66U (Merlin) - сервер
Сеть на даче 192.168.0.0, роутер Xiaomi, прошивка Padavan - клиент
ifconfig сервер
maxim@RT-N66U-3218:/tmp/home/root# ifconfig
br0 Link encap:Ethernet HWaddr AC:22:0B:34:32:18
inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
RX packets:439616 errors:0 dropped:0 overruns:0 frame:0
TX packets:387681 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:96872487 (92.3 MiB) TX bytes:85740709 (81.7 MiB)
eth0 Link encap:Ethernet HWaddr AC:22:0B:34:32:18
inet addr:37.57.xx.xx Bcast:37.57.xx.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:32540179 errors:0 dropped:0 overruns:0 frame:0
TX packets:47093791 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3349418990 (3.1 GiB) TX bytes:309476575 (295.1 MiB)
Interrupt:4 Base address:0x2000
eth1 Link encap:Ethernet HWaddr AC:22:0B:34:32:18
UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
RX packets:43640350 errors:0 dropped:0 overruns:0 frame:1250077
TX packets:10572747 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1837717151 (1.7 GiB) TX bytes:3057497858 (2.8 GiB)
Interrupt:3 Base address:0x8000
eth2 Link encap:Ethernet HWaddr AC:22:0B:34:32:1C
UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
Interrupt:5 Base address:0x8000
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MULTICAST MTU:16436 Metric:1
RX packets:46258 errors:0 dropped:0 overruns:0 frame:0
TX packets:46258 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:9285118 (8.8 MiB) TX bytes:9285118 (8.8 MiB)
tun21 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.8.0.1 P-t-P:10.8.0.1 Mask:255.255.255.0
UP POINTOPOINT RUNNING NOARP PROMISC MULTICAST MTU:1500 Metric:1
RX packets:37 errors:0 dropped:0 overruns:0 frame:0
TX packets:93 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1924 (1.8 KiB) TX bytes:5440 (5.3 KiB)
vlan1 Link encap:Ethernet HWaddr AC:22:0B:34:32:18
UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
RX packets:20160668 errors:0 dropped:0 overruns:0 frame:0
TX packets:45411973 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:3063306943 (2.8 GiB) TX bytes:4183231680 (3.8 GiB)
wl0.1 Link encap:Ethernet HWaddr AC:22:0B:34:32:19
UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
RX packets:70526 errors:0 dropped:0 overruns:0 frame:1250077
TX packets:373746 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:10335476 (9.8 MiB) TX bytes:487418683 (464.8 MiB)
ifconfig клиент
/home/root # ifconfig
br0 Link encap:Ethernet HWaddr 28:6C:07:31:4B:C8
inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:17001 errors:0 dropped:0 overruns:0 frame:0
TX packets:17943 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:4017726 (3.8 MiB) TX bytes:6353203 (6.0 MiB)
eth2 Link encap:Ethernet HWaddr 28:6C:07:31:4B:C8
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:15230 errors:0 dropped:0 overruns:0 frame:0
TX packets:19496 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:4123829 (3.9 MiB) TX bytes:4872263 (4.6 MiB)
Interrupt:5
eth2.1 Link encap:Ethernet HWaddr 28:6C:07:31:4B:C8
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:4264 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:716372 (699.5 KiB)
eth2.2 Link encap:Ethernet HWaddr 28:6C:07:31:4B:CB
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:8 errors:0 dropped:0 overruns:0 frame:0
TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:691 (691.0 B) TX bytes:691 (691.0 B)
ra0 Link encap:Ethernet HWaddr 28:6C:07:31:4B:C9
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:14601 errors:0 dropped:0 overruns:0 frame:0
TX packets:13350 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3813168 (3.6 MiB) TX bytes:4408248 (4.2 MiB)
Interrupt:6
rai0 Link encap:Ethernet HWaddr 28:6C:07:31:4B:CA
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:3995 errors:0 dropped:0 overruns:0 frame:0
TX packets:3575 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:828922 (809.4 KiB) TX bytes:1259154 (1.2 MiB)
Interrupt:4
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.8.0.2 P-t-P:10.8.0.2 Mask:255.255.255.0
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:298 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:0 (0.0 B) TX bytes:15830 (15.4 KiB)
weth0 Link encap:Ethernet HWaddr 0C:5B:8F:27:9A:64
inet addr:192.168.8.100 Bcast:192.168.8.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:15028 errors:0 dropped:0 overruns:0 frame:0
TX packets:12912 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:5464735 (5.2 MiB) TX bytes:3684827 (3.5 MiB)
netstat -rn сервера
/tmp/home/root# netstat -rn
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
37.57.xx.xx 0.0.0.0 255.255.255.255 UH 0 0 0 eth0
10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun21
37.57.xx.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun21
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo
0.0.0.0 37.57.xx.xx 0.0.0.0 UG 0 0 0 eth0
конфиг сервера OpenVpn
# Automatically generated configuration
daemon
topology subnet
server 10.8.0.0 255.255.255.0
proto udp
port 1194
dev tun21
ncp-ciphers AES-128-GCM:AES-256-GCM:AES-128-CBC:AES-256-CBC
cipher AES-128-CBC
comp-lzo adaptive
keepalive 15 60
verb 3
push "route 192.168.1.0 255.255.255.0 vpn_gateway 500"
client-config-dir ccd
client-to-client
duplicate-cn
plugin /usr/lib/openvpn-plugin-auth-pam.so openvpn
verify-client-cert none
username-as-common-name
ca ca.crt
dh dh.pem
cert server.crt
key server.key
script-security 2
up updown.sh
down updown.sh
status-version 2
status status 5
# Custom Configuration
route 192.168.0.0 255.255.255.0 vpn_gateway
на сервере создал директорию /jffs/openvpn/ccd/ и положил туда файл с именем пользователя OpenVPN, внутри
iroute 192.168.0.0 255.255.255.0