<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: How to configure OpenVPN</title>
	<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/</link>
	<description>What would they do without us...</description>
	<pubDate>Wed, 10 Mar 2010 23:19:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
		<item>
		<title>By: jojoba</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-305</link>
		<dc:creator>jojoba</dc:creator>
		<pubDate>Sun, 08 Mar 2009 05:57:07 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-305</guid>
		<description>Wonderful article! Only qualms, you could explain the "TAP" acronym - it's not as common as "DNS" and "DHCP." Other qualm: a bit more explanation on the DynDNS part. Like, "DynDNS" is a service you can subscribe to that will keep track of your dynamic IP from your ISP and associate it with a DNS name; so that, if/when your DSL or Cable Modem ip address changes, DynDNS will track that change, and will update your corresponding public DNS name with the new address that your ISP has assigned to your external interface."

Anyway, I think that's my guess on what the DynDNS does, from some things I've read in the past, and I've been meaning to try it, and now, thanks to your superb tutorial, I have a good reason. :) Also note: You could mention that, "Oh, btw, even if you don't have a static IP addre, you [can] find your current external IP address of your home network by surfing to "http://www.whatismyip.com" - and you can enter that in the config files." WARNING: That address is subject to change but, until it changes, your VPN connections will work.

OR... if you DON'T want to deal with DynDNS and you DON'T want pay the extra $5 /month for a static IP (or you have cable and they don't offer static IP), you can just setup a scheduled daily job on your server to grab your current external IP and "blat" it (email it) to one of your public email accounts, say, once per day - that way, you always will be able to hop on your email and see your current public IP is - in case you have to modify your client VPN configs. Okay, it's funky, but it works. 

Bottom line: RILEY - YOU ROCK! Now, let's find equivalent steps for D-Link &#38; DSL routers. I have a Netopia DSL router I would like to set this up on, and some D-Link routers also.

many thanks!</description>
		<content:encoded><![CDATA[<p>Wonderful article! Only qualms, you could explain the &#8220;TAP&#8221; acronym - it&#8217;s not as common as &#8220;DNS&#8221; and &#8220;DHCP.&#8221; Other qualm: a bit more explanation on the DynDNS part. Like, &#8220;DynDNS&#8221; is a service you can subscribe to that will keep track of your dynamic IP from your ISP and associate it with a DNS name; so that, if/when your DSL or Cable Modem ip address changes, DynDNS will track that change, and will update your corresponding public DNS name with the new address that your ISP has assigned to your external interface.&#8221;</p>
<p>Anyway, I think that&#8217;s my guess on what the DynDNS does, from some things I&#8217;ve read in the past, and I&#8217;ve been meaning to try it, and now, thanks to your superb tutorial, I have a good reason. :) Also note: You could mention that, &#8220;Oh, btw, even if you don&#8217;t have a static IP addre, you [can] find your current external IP address of your home network by surfing to &#8220;http://www.whatismyip.com&#8221; - and you can enter that in the config files.&#8221; WARNING: That address is subject to change but, until it changes, your VPN connections will work.</p>
<p>OR&#8230; if you DON&#8217;T want to deal with DynDNS and you DON&#8217;T want pay the extra $5 /month for a static IP (or you have cable and they don&#8217;t offer static IP), you can just setup a scheduled daily job on your server to grab your current external IP and &#8220;blat&#8221; it (email it) to one of your public email accounts, say, once per day - that way, you always will be able to hop on your email and see your current public IP is - in case you have to modify your client VPN configs. Okay, it&#8217;s funky, but it works. </p>
<p>Bottom line: RILEY - YOU ROCK! Now, let&#8217;s find equivalent steps for D-Link &amp; DSL routers. I have a Netopia DSL router I would like to set this up on, and some D-Link routers also.</p>
<p>many thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mich2212001</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-304</link>
		<dc:creator>mich2212001</dc:creator>
		<pubDate>Mon, 29 Dec 2008 18:28:13 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-304</guid>
		<description>this is a great help ... i have been trying to make sense of Openvpn for a long time now. thanks for the help. however, i have a cisco 1721 router in charge of DHCP. &#38; i do have a local Domain with dns server configured as well. my question is how do i go about configuring the server to work with that .... please help</description>
		<content:encoded><![CDATA[<p>this is a great help &#8230; i have been trying to make sense of Openvpn for a long time now. thanks for the help. however, i have a cisco 1721 router in charge of DHCP. &amp; i do have a local Domain with dns server configured as well. my question is how do i go about configuring the server to work with that &#8230;. please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wasser</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-303</link>
		<dc:creator>Wasser</dc:creator>
		<pubDate>Sun, 03 Aug 2008 23:42:28 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-303</guid>
		<description>Hi!
I have the following problem:
I configured everything [almost] like you said, but when I go to the Routing table on my dir-655 (I went to Advanced/Routing, think it's the same) and fill everything, it says that the ip of the gateway is not on the same subnet of the interface. The interface is fixed on WAN and the router does not allow me to change it. The only IP I could fill for the gateway was my external IP, but it's not working...
Help?</description>
		<content:encoded><![CDATA[<p>Hi!<br />
I have the following problem:<br />
I configured everything [almost] like you said, but when I go to the Routing table on my dir-655 (I went to Advanced/Routing, think it&#8217;s the same) and fill everything, it says that the ip of the gateway is not on the same subnet of the interface. The interface is fixed on WAN and the router does not allow me to change it. The only IP I could fill for the gateway was my external IP, but it&#8217;s not working&#8230;<br />
Help?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: glenn0</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-301</link>
		<dc:creator>glenn0</dc:creator>
		<pubDate>Thu, 17 Jul 2008 06:39:00 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-301</guid>
		<description>Hey guys,

I used this guide to setup my VPN (thanks Riley!) but made a few security enhancements along the way. I decided to write up a version of Riley's guide with my additions. I hope that's ok Riley.

I've added TLS-Auth, password protected 2048-bit keys, AES encryption and explanations in a lot of sections.

It seems you can't post links in comments here, but if you Google "openvpn lockup", my blog (called lockup) will be the first result.

Hope it helps.</description>
		<content:encoded><![CDATA[<p>Hey guys,</p>
<p>I used this guide to setup my VPN (thanks Riley!) but made a few security enhancements along the way. I decided to write up a version of Riley&#8217;s guide with my additions. I hope that&#8217;s ok Riley.</p>
<p>I&#8217;ve added TLS-Auth, password protected 2048-bit keys, AES encryption and explanations in a lot of sections.</p>
<p>It seems you can&#8217;t post links in comments here, but if you Google &#8220;openvpn lockup&#8221;, my blog (called lockup) will be the first result.</p>
<p>Hope it helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abc</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-299</link>
		<dc:creator>abc</dc:creator>
		<pubDate>Wed, 16 Jul 2008 19:52:15 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-299</guid>
		<description>How to share óne vpn client connection to multiple pcs?

I’m connected to an openVPN Server using the openvpn client (dev tun).
The client pc(xp sp2) has 2 nics. one to connect to lan/adsl &#38; the
other to connect to a voice gateway (spa3102)via crossover. How can I
configure the spa3102 connected over nic2 to go through only the open
vpn connection to connect to its sip server? or in other words how can
i share the open vpn client connection?</description>
		<content:encoded><![CDATA[<p>How to share óne vpn client connection to multiple pcs?</p>
<p>I’m connected to an openVPN Server using the openvpn client (dev tun).<br />
The client pc(xp sp2) has 2 nics. one to connect to lan/adsl &amp; the<br />
other to connect to a voice gateway (spa3102)via crossover. How can I<br />
configure the spa3102 connected over nic2 to go through only the open<br />
vpn connection to connect to its sip server? or in other words how can<br />
i share the open vpn client connection?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bebopblues</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-294</link>
		<dc:creator>bebopblues</dc:creator>
		<pubDate>Wed, 28 May 2008 09:30:09 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-294</guid>
		<description>Riley, first off, many thanks for the tutorial and providing the sample config files. I followed your instructions carefully and established connections between server and clients. The only problem I have is what peter stated a few posts above, my internet dies when openvpn is connected. If I disconnect openvpn, then internet works again. I've tried on several local machines, and all seems to be the same problem. Now this only happens on local machines on the local network with the server. I tested a machine outside the network, and it does not lose internet connection, it works perfectly.

Regarding the DNS settings, I used the WAN DNS settings from my cable modem, I'm assuming thats the correct one and not the local gateway (192.168.1.1). I've been trying to figure out why the local machines lose internet connection, but I'm still scratching my head and clueless. If you have advice to solve this issue, please reply. Much appreciated.</description>
		<content:encoded><![CDATA[<p>Riley, first off, many thanks for the tutorial and providing the sample config files. I followed your instructions carefully and established connections between server and clients. The only problem I have is what peter stated a few posts above, my internet dies when openvpn is connected. If I disconnect openvpn, then internet works again. I&#8217;ve tried on several local machines, and all seems to be the same problem. Now this only happens on local machines on the local network with the server. I tested a machine outside the network, and it does not lose internet connection, it works perfectly.</p>
<p>Regarding the DNS settings, I used the WAN DNS settings from my cable modem, I&#8217;m assuming thats the correct one and not the local gateway (192.168.1.1). I&#8217;ve been trying to figure out why the local machines lose internet connection, but I&#8217;m still scratching my head and clueless. If you have advice to solve this issue, please reply. Much appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: compsafe</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-293</link>
		<dc:creator>compsafe</dc:creator>
		<pubDate>Fri, 23 May 2008 01:56:22 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-293</guid>
		<description>Hi, i am trying to configure openvpn and having some queries. For the Intial set up; i configured my desktop as server and laptop as a client, which works fine.Now,I want to take it to the next step. I want the client to connect to my desktop and should be able to access the main webserver throgh my PC. Thatis my PC should be able to act as an interface to allow the laptop to connect the main webserver. Please help. What changes should i make in the congig.files.</description>
		<content:encoded><![CDATA[<p>Hi, i am trying to configure openvpn and having some queries. For the Intial set up; i configured my desktop as server and laptop as a client, which works fine.Now,I want to take it to the next step. I want the client to connect to my desktop and should be able to access the main webserver throgh my PC. Thatis my PC should be able to act as an interface to allow the laptop to connect the main webserver. Please help. What changes should i make in the congig.files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shukalo83</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-292</link>
		<dc:creator>shukalo83</dc:creator>
		<pubDate>Tue, 13 May 2008 17:57:09 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-292</guid>
		<description>Thank You really on such a great tutorial. I think it's unique in its simplicity and effectiveness. Everything work flawless for me but when I try to connect from Windows XP client that has no admin privileges the virtual tap interface doesn't get the default gateway by DHCP. When I am admin from the same machine, everything works perfectly. I don't know what could be the problem. I installed openvpn gui as an administrator on the client side. So once more, to be specific, I received client address by dhcp  192.168.10.3 but i don't have def gateway of 192.168.10.1 an that only when I am not logged in as an administrator. I realize that this tutorial is a bit old but there are maybe someone outhere who is willing to give me a hand. Thanks in advance</description>
		<content:encoded><![CDATA[<p>Thank You really on such a great tutorial. I think it&#8217;s unique in its simplicity and effectiveness. Everything work flawless for me but when I try to connect from Windows XP client that has no admin privileges the virtual tap interface doesn&#8217;t get the default gateway by DHCP. When I am admin from the same machine, everything works perfectly. I don&#8217;t know what could be the problem. I installed openvpn gui as an administrator on the client side. So once more, to be specific, I received client address by dhcp  192.168.10.3 but i don&#8217;t have def gateway of 192.168.10.1 an that only when I am not logged in as an administrator. I realize that this tutorial is a bit old but there are maybe someone outhere who is willing to give me a hand. Thanks in advance</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: openfish</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-291</link>
		<dc:creator>openfish</dc:creator>
		<pubDate>Sat, 12 Apr 2008 17:27:10 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-291</guid>
		<description>Thank you Riley for the well defined VPN set up using OpenVpn. 
Though my actual job is to create a site-to-site VPN using OpenVPN,  first I tried between two computers within the same LAN, one as the server and the other as a client.
The network address of  my LAN is 192.168.1.0. And the pcs' address is 192.168.1.x1 and 192.168.1.x2. And I used virtual address( with its netmask) 10.8.0.0 255.255.255.0.
I successfully established the VPN between the two computers, that is, when I tried to 
 ping using the IP of virtual tunnel 10.8.0.1 to other machine whose vpn tunnel ip (virtual ) is 10.8.0.2 it works fine and it works also from other direction. 


Again, when i tried to ping byHost ID 192.168.1.12 to other host ID 192.168.1.133 it also pings normally


As per OpenVPN when tunnel get created all traffic should run between the tunnel.
what i guess by this
only Pinging is possible through virtual Ip adresses of the tunnel

not through the actual host ID like 192.168.1.12 to 192.168.1.133  between the two machines if virtual tunnel is already established.

My first question is, is it possible to ping using normal host id, in addition to using virtual address, while tunnel is already created?

My second question, even other machines can ping to the tunneled machines( to the OpenVPN server and client); and the server and the client can ping normally to the other PCs in the LAN using the their host IP addresses. 
What I guessed was, only the machines in the tunnel can only ping one another, nothing else, , though they are physically connected in the LAN.
Is it possible, with explanations?
I am looking forward to reading your replies.

Thank you, forum members, in advance.</description>
		<content:encoded><![CDATA[<p>Thank you Riley for the well defined VPN set up using OpenVpn.<br />
Though my actual job is to create a site-to-site VPN using OpenVPN,  first I tried between two computers within the same LAN, one as the server and the other as a client.<br />
The network address of  my LAN is 192.168.1.0. And the pcs&#8217; address is 192.168.1.x1 and 192.168.1.x2. And I used virtual address( with its netmask) 10.8.0.0 255.255.255.0.<br />
I successfully established the VPN between the two computers, that is, when I tried to<br />
 ping using the IP of virtual tunnel 10.8.0.1 to other machine whose vpn tunnel ip (virtual ) is 10.8.0.2 it works fine and it works also from other direction. </p>
<p>Again, when i tried to ping byHost ID 192.168.1.12 to other host ID 192.168.1.133 it also pings normally</p>
<p>As per OpenVPN when tunnel get created all traffic should run between the tunnel.<br />
what i guess by this<br />
only Pinging is possible through virtual Ip adresses of the tunnel</p>
<p>not through the actual host ID like 192.168.1.12 to 192.168.1.133  between the two machines if virtual tunnel is already established.</p>
<p>My first question is, is it possible to ping using normal host id, in addition to using virtual address, while tunnel is already created?</p>
<p>My second question, even other machines can ping to the tunneled machines( to the OpenVPN server and client); and the server and the client can ping normally to the other PCs in the LAN using the their host IP addresses.<br />
What I guessed was, only the machines in the tunnel can only ping one another, nothing else, , though they are physically connected in the LAN.<br />
Is it possible, with explanations?<br />
I am looking forward to reading your replies.</p>
<p>Thank you, forum members, in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: minardi</title>
		<link>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-290</link>
		<dc:creator>minardi</dc:creator>
		<pubDate>Fri, 04 Apr 2008 13:20:07 +0000</pubDate>
		<guid>http://www.itsatechworld.com/2006/01/29/how-to-configure-openvpn/#comment-290</guid>
		<description>Hi.

I have the exact same setup as in this guide, and everything is working except when i connect the client to the server, i loose all internet on the client, yet i still have connection to the server.

I have put in the DNS information on the server config, and it sends the DNS info to the client, yet it still isnt getting any internet connection.</description>
		<content:encoded><![CDATA[<p>Hi.</p>
<p>I have the exact same setup as in this guide, and everything is working except when i connect the client to the server, i loose all internet on the client, yet i still have connection to the server.</p>
<p>I have put in the DNS information on the server config, and it sends the DNS info to the client, yet it still isnt getting any internet connection.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
