[S] Change in openvpn[master]: push: push route-gateway(s) and server route(s) for subnet-pool clients

"ordex \(Code Review\) via Openvpn-devel" <[email protected]>
Newsgroups gmane.network.openvpn.devel
Message-ID <[email protected]>
Attention is currently required from: plaisthos.

Hello plaisthos,

I'd like you to do a code review.
Please visit

    http://gerrit.openvpn.net/c/openvpn/+/1787?usp=email

to review the following change.


Change subject: push: push route-gateway(s) and server route(s) for subnet-pool clients
......................................................................

push: push route-gateway(s) and server route(s) for subnet-pool clients

A subnet-pool client sits outside the --server / --server-ipv6 network,
so the global route-gateway (the server's own VPN IP) is off-link for
it. Push a route-gateway, and for IPv6 a route-ipv6-gateway, inside the
client's own subnet, plus a host route back to the server's VPN IPv4 and
IPv6, so the client's pushed routes install and the server stays
reachable.

Change-Id: I7c0ff48fb019ac7c2d1d981b7b7e4578ff5dce48
GitHub: closes openvpn/OpenVPN#987
Signed-off-by: Antonio Quartulli <[email protected]>
---
M src/openvpn/push.c
1 file changed, 30 insertions(+), 0 deletions(-)



  git pull ssh://gerrit.openvpn.net:29418/openvpn refs/changes/87/1787/1

diff --git a/src/openvpn/push.c b/src/openvpn/push.c
index e391147..7e26c79 100644
--- a/src/openvpn/push.c
+++ b/src/openvpn/push.c
@@ -645,6 +645,20 @@
                         print_in6_addr(c->c2.push_ifconfig_ipv6_local, 0, gc),
                         c->c2.push_ifconfig_ipv6_netbits,
                         print_in6_addr(c->c2.push_ifconfig_ipv6_remote, 0, gc));
+
+        /* subnet-pool-ipv6 counterpart of the IPv4 push below: a route-ipv6-
+         * gateway inside the client's own subnet and a host route back to the
+         * server's VPN IPv6, so pushed routes install and it stays reachable. */
+        if (o->subnet_pool_ipv6_defined && c->c1.tuntap)
+        {
+            /* drop any global route-ipv6-gateway: it is off-link for this
+             * client, so replace rather than merely override it */
+            push_remove_option(o, "route-ipv6-gateway");
+            push_option_fmt(gc, push_list, M_USAGE, "route-ipv6-gateway %s",
+                            print_in6_addr(o->subnet_pool_ipv6_gateway, 0, gc));
+            push_option_fmt(gc, push_list, M_USAGE, "route-ipv6 %s/128",
+                            print_in6_addr(c->c1.tuntap->local_ipv6, 0, gc));
+        }
     }
 
     /* ipv4 */
@@ -659,6 +673,22 @@
         push_option_fmt(gc, push_list, M_USAGE, "ifconfig %s %s",
                         print_in_addr_t(ifconfig_local, 0, gc),
                         print_in_addr_t(c->c2.push_ifconfig_remote_netmask, 0, gc));
+
+        /* A subnet-pool client sits outside the --server network: push a
+         * route-gateway inside its own subnet and a host route back to the
+         * server's VPN IP, so pushed routes install on-link and the server
+         * stays reachable. */
+        if (o->subnet_pool_defined && c->c1.tuntap)
+        {
+            /* drop the global route-gateway (the server's own VPN IP): it is
+             * off-link for this client, so replace rather than merely override
+             * it in the push string */
+            push_remove_option(o, "route-gateway");
+            push_option_fmt(gc, push_list, M_USAGE, "route-gateway %s",
+                            print_in_addr_t(o->subnet_pool_gateway, 0, gc));
+            push_option_fmt(gc, push_list, M_USAGE, "route %s 255.255.255.255",
+                            print_in_addr_t(c->c1.tuntap->local, 0, gc));
+        }
     }
 
     if (tls_multi->use_peer_id)

-- 
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1787?usp=email
To unsubscribe, or for help writing mail filters, visit http://gerrit.openvpn.net/settings?usp=email

Gerrit-MessageType: newchange
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: I7c0ff48fb019ac7c2d1d981b7b7e4578ff5dce48
Gerrit-Change-Number: 1787
Gerrit-PatchSet: 1
Gerrit-Owner: ordex <[email protected]>
Gerrit-Reviewer: plaisthos <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-Attention: plaisthos <[email protected]>

_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.