<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN Remote Access Tap Bridge]]></title><description><![CDATA[<p dir="auto">I've configured the OpenVPN server as folows:<br />
<strong>Server Mode:</strong> Remote Access ( SSL/TLS )<br />
<strong>Protocol:</strong> URP<br />
<strong>Device Mode:</strong> tap<br />
<strong>Interface:</strong> (CARP Virtual IP)<br />
<strong>Local Port:</strong> 1194<br />
<strong>IPv4/6 Tunnel Network:</strong> &lt;empty&gt;<strong>Bridge DHCP:</strong> Enabled<br />
<strong>Bridge Interface:</strong> &lt;interface with="" dhcp="" enabled=""&gt;<strong>Server Bridge DHCP Start &amp; End:</strong> &lt;empty&gt;<strong>Redirect Gateway:</strong> Disabled<br />
<strong>IPv4 Local Networks:</strong> 172.16.0.0/16,172.17.0.0/16,172.20.0.0/16,172.21.0.0/16,172.22.0.0/16<br />
<strong>IPv6 Local Networks:</strong> &lt;empty&gt;<strong>Concurrent connections:</strong> &lt;empty&gt;<strong>Compression:</strong> Enabled (doesn't matter)<br />
<strong>Type-of-Service:</strong> Enabled (doesn't matter)<br />
<strong>Inter-client communication:</strong> Enabled (doesn't matter)<br />
<strong>Client Settings:</strong> All disabled</p>
<p dir="auto">The client can connect but doesn't get an IP. Adding the routes throws errors but that is probably due to not having an IP.<br />
Setting the IP manually on the client doesn't work either. Received packages: 0<br />
All interfaces got an Allow IPv4* rule with logging enabled. No packages are logged (except for WAN ofcourse)</p>
<p dir="auto">Disabling the bridge mode for OpenVPN, configuring a tunnel network and setting "Provide a virtual adapter IP address to clients (see Tunnel Network)" Enabled works just fine. The client gets an IP, the routes get added and I can connect to hosts on the other side.&lt;/empty&gt;&lt;/empty&gt;&lt;/empty&gt;&lt;/interface&gt;&lt;/empty&gt;</p>
]]></description><link>https://forum.netgate.com/topic/53561/openvpn-remote-access-tap-bridge</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 11:27:22 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/53561.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 26 Feb 2013 19:04:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN Remote Access Tap Bridge on Wed, 27 Feb 2013 20:35:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>:</p>
<blockquote>
<p dir="auto">Do you get an IP if you're bridging and fill in the server bridge dhcp start/end?</p>
<p dir="auto">If you do, then check your actual DHCP sever logs to see if it's being rejected for some reason there.</p>
<p dir="auto">Make sure you read/understand the note under the bridge interface selector.</p>
</blockquote>
<p dir="auto">I thought I tried and read everything ::)</p>
<p dir="auto">Thank you!<br />
I didn't create the bridge interface necessary for the connection… Now I'm afraid to open a new topic for another bridging thing I keep failing at. I'll just keep messing with that one :P</p>
<p dir="auto">For other people running into this; Create the bridge!<br />
If you are running into the error:</p>
<pre><code>OpenVPN Route: OpenVPN needs a gateway parameter for a --route option and no default was specified
OpenVPN Route: Failed to parse/resolve route for host network: ***
</code></pre>
<p dir="auto">Define the DHCP start and end options.</p>
<p dir="auto">//Edit:<br />
Is it normal that interfaces with IP set to "None" have their own undeletable gateway and spawn syslog messages?</p>
<pre><code>Feb 27 21:09:50 	php: : rc.newwanip: Failed to update opt10 IP, restarting...
Feb 27 21:09:50 	php: : rc.newwanip: on (IP address: ) (interface: opt10) (real interface: ovpns1).
Feb 27 21:09:50 	php: : rc.newwanip: Informational is starting ovpns1.
</code></pre>
<p dir="auto">//Edit2:<br />
Also, when applying these settings, a random CARP VIP goes down:</p>
<pre><code>Feb 27 21:26:41 	kernel: opt2_vip1: link state changed to DOWN
Feb 27 21:26:41 	kernel: opt2_vip1: INIT -&gt; BACKUP
Feb 27 21:26:41 	kernel: opt2_vip1: link state changed to DOWN
</code></pre>
<p dir="auto">The first time I configured the OpenVPN bridging, I thought it could have been because I accidentally had the bridged interface in OpenVPN Settings configured to the interface opt2 for a minute. The second time though, I had left the OpenVPN settings bridged to the correct network and was extra cautious with creating the bridges but the same VIP still went down. There is no special reason for <em>that</em> interfaces VIP to be affected, I have other interfaces configured exactly the same. The only thing I can think of is that this is VIP1.<br />
The solution was to 'edit' the settings for opt2, change nothing and apply settings.</p>
<p dir="auto">The error seems to come from syncing the configuration to the other firewall:</p>
<pre><code>Feb 27 21:26:41 	kernel: opt2_vip1: link state changed to DOWN
Feb 27 21:26:41 	kernel: opt2_vip1: INIT -&gt; BACKUP
Feb 27 21:26:41 	kernel: opt2_vip1: link state changed to DOWN
Feb 27 21:26:41 	php: : Beginning XMLRPC sync to https://172.20.1.2:9180.
Feb 27 21:26:38 	check_reload_status: Syncing firewall
Feb 27 21:19:20 	php: : Filter sync successfully completed with https://172.20.1.2:9180.
Feb 27 21:19:12 	php: : XMLRPC sync successfully completed with https://172.20.1.2:9180.
</code></pre>
<p dir="auto">Firewall 2 on 172.20.1.2 did not have the interface configuration yet at that time. When fixing the issue by 'editing' the opt2 interface, the correct configuration was already applied to the second firewall.</p>
<p dir="auto">Funny thing is that FW1 shows the CARP IP to be down and generates a notification of a failing sync but FW2 doesn't even have a log entry of it.</p>
]]></description><link>https://forum.netgate.com/post/381725</link><guid isPermaLink="true">https://forum.netgate.com/post/381725</guid><dc:creator><![CDATA[Joolee]]></dc:creator><pubDate>Wed, 27 Feb 2013 20:35:18 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN Remote Access Tap Bridge on Wed, 27 Feb 2013 15:21:27 GMT]]></title><description><![CDATA[<p dir="auto">Do you get an IP if you're bridging and fill in the server bridge dhcp start/end?</p>
<p dir="auto">If you do, then check your actual DHCP sever logs to see if it's being rejected for some reason there.</p>
<p dir="auto">Make sure you read/understand the note under the bridge interface selector.</p>
]]></description><link>https://forum.netgate.com/post/381720</link><guid isPermaLink="true">https://forum.netgate.com/post/381720</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 27 Feb 2013 15:21:27 GMT</pubDate></item></channel></rss>