push "ifconfig 172.31.1.1 255.255.0.0";
ifconfig-push 172.31.1.1 255.255.0.0
iroute 172.30.255.0 255.255.255.0
push " iroute 172.30.255.0 255.255.255.0";
dev tun
persist-tun
persist-key
# 2.4.9 version => data-ciphers
#data-ciphers AES-128-GCM
#data-ciphers-fallback AES-128-GCM
# 2.4.7 version => cipher
cipher AES-128-GCM
# Set client local port
lport 61194
auth SHA256
tls-client
client
resolv-retry infinite
remote vpn.vitko-core.ru 61194 udp4
verify-x509-name "vpn.vitko-core.ru" name
auth-user-pass LAN.auth
remote-cert-tls server
[2.4.5-RELEASE][root@pfSense.vitko-core.ru]/root: netstat -rn
Routing tables
Internet:
Destination Gateway Flags Netif Expire
default 95.153.104.1 UGS igb0
1.1.1.3 95.153.104.1 UGHS igb0
95.153.104.0/21 link#1 U igb0
95.153.111.12 link#1 UHS lo0
127.0.0.1 link#7 UH lo0
172.30.255.0/24 172.31.1.1 UGS ovpns1
172.31.0.0/16 172.31.0.2 UGS ovpns1
172.31.0.1 link#11 UHS lo0
172.31.0.2 link#11 UH ovpns1
192.168.255.0/24 link#2 U igb1
192.168.255.254 link#2 UHS lo0
Internet6:
Destination Gateway Flags Netif Expire
::1 link#7 UH lo0
fe80::%igb0/64 link#1 U igb0
fe80::2e0:5cff:fe68:1733%igb0 link#1 UHS lo0
fe80::%igb1/64 link#2 U igb1
fe80::1:1%igb1 link#2 UHS lo0
fe80::%lo0/64 link#7 U lo0
fe80::1%lo0 link#7 UHS lo0
fe80::2e0:5cff:fe68:1733%ovpns1 link#11 UHS lo0
[2.4.5-RELEASE][root@pfSense.vitko-core.ru]/root: traceroute 172.30.255.1
traceroute to 172.30.255.1 (172.30.255.1), 64 hops max, 40 byte packets
1 *^C
[2.4.5-RELEASE][root@pfSense.vitko-core.ru]/root: route get 172.30.255.1
route to: 172.30.255.1
destination: 172.30.255.0
mask: 255.255.255.0
gateway: 172.31.1.1
fib: 0
interface: ovpns1
flags: <UP,GATEWAY,DONE,STATIC>
recvpipe sendpipe ssthresh rtt,msec mtu weight expire
0 0 0 0 1500 1 0
[2.4.5-RELEASE][root@pfSense.vitko-core.ru]/root: traceroute 172.30.255.1
traceroute to 172.30.255.1 (172.30.255.1), 64 hops max, 40 byte packets
1 * * *
2 * * *
3 * * *
4 * * *
5 *