tak pokud jsem se nikde nesekl, melo by fungovat toto:
server
------
proto tcp #nebo tcp-server, zalezi na verzi openvpn
dev tun
ca /root/openvpn/ca.crt
cert /root/openvpn/server.crt
key /root/openvpn/server.key
dh /root/openvpn/dh1024.pem
server 172.17.88.0 255.255.255.0 #sit se rozdeli na \30 podsite, pricemz .1 je vzdy server.
#pak bude .0-sit serveru,.1-server,.2-tunel na serveru,.3-broadcast
#.4-sit klienta 1,.5-tunel na klienta1,.6-ip klienta1,.7-broadcast
#.8-sit klienta 2,.9-tunel na klienta2,.10-ip klienta2,.11-broadcast,...
push "redirect-gateway def1" #donuceni klientu k presmerovani toku pres server
push "dhcp-option DNS 10.200.0.254" #pripadne 10.0.0.255, kterou vyuziva i server, nevim jaky DNS pouzivate
#pokud ma byt server zaroven i DNS, potrebujete jeste nejaky
#DNS (proxy) server (bind, nebo jednodussi dnsmasq,
# ale ten je zaroven i dhcp, i kdyz to lze vypnout)
keepalive 10 120
cipher AES-256-CBC # silnejsi AES
comp-lzo
ifconfig-pool-persist openvpn-ipp.txt #db IP klientu
duplicate-cn
client-to-client
user nobody
group nogroup
persist-key
persist-tun
status openvpn-status.log #aktivni relace
verb 3
----------------------------------------------------
klient
------
client
dev tun
proto tcp
remote XY 1194
resolv-retry 10
nobind
persist-key
ca "ca.crt"
cert "klient1.crt"
key "klient1.key"
cipher AES-256-CBC
comp-lzo
verb 3
ostatni IP adresy v ostatnich sitich jsou z VPN dostupne, pokud na ne muze i server...