<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN in tap server mode]]></title><description><![CDATA[<p dir="auto">We use OpenVPN here, primarily in tap (bridging) mode.</p>
<p dir="auto">I seem to recall from some time ago that support for tap was to be included in 2.0; I found that it seems to have been included for client mode, but not for the server side.  I generated a configuration with some minor fiddling on the client side that appeared to result in traffic being sent to the server, but the server side appeared to be a little messier.  In particular, while I think I had the OpenVPN incantation correct, the pf firewall was blocking inbound traffic, and trying to add firewall rules for "OpenVPN" wasn't working because that is applied to the "ovpns*" interfaces but my incantation was resulting in a "tap*" interface.  Trying to generate "easy" rules didn't work either, ending at an error page.</p>
<p dir="auto">Was this still intended for inclusion in 2.0?  I can deploy our working kludge on 1.2.3 if needed, but had been hoping to get this working under 2.0.</p>
]]></description><link>https://forum.netgate.com/topic/30977/openvpn-in-tap-server-mode</link><generator>RSS for Node</generator><lastBuildDate>Fri, 06 Mar 2026 17:45:17 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/30977.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Feb 2011 04:23:40 GMT</pubDate><ttl>60</ttl></channel></rss>