*nat
:PREROUTING ACCEPT [11:869]
:POSTROUTING ACCEPT [1:60]
:OUTPUT ACCEPT [1:60]
-A POSTROUTING -s
10.0.1.0/24 -o eno16777728 -j MASQUERADE
-A POSTROUTING -s
10.0.1.0/24 -o tun1 -j MASQUERADE
COMMIT
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state —state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
# SSH
-A INPUT -m state —state NEW -m tcp -p tcp —dport 22 -j ACCEPT
# OpenVPN - HeadQuaters & VPN Clients
-A INPUT -m state —state NEW -m udp -p udp —dport 30033 -j ACCEPT
-A INPUT -m state —state NEW -m tcp -p tcp —dport 30033 -j ACCEPT
-A INPUT -j REJECT —reject-with icmp-host-prohibited
-A FORWARD -j REJECT —reject-with icmp-host-prohibited
COMMIT
На клиенте
==========
Активные маршруты:
Сетевой адрес Маска сети Адрес шлюза Интерфейс Метрика
0.0.0.0 0.0.0.0 192.168.22.1 192.168.22.6 35
10.0.1.0 255.255.255.0 On-link
10.0.1.2 291
10.0.1.2 255.255.255.255 On-link
10.0.1.2 291
10.0.1.255 255.255.255.255 On-link
10.0.1.2 291
На сервере
==========
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.2.1 0.0.0.0 eno16777728
10.0.0.2 0.0.0.0 255.255.255.255 tun0
10.0.1.0 0.0.0.0 255.255.255.0 tun1
192.168.2.0 0.0.0.0 255.255.255.0 eno16777728
ifconfig
eno16777728: f
inet
192.168.2.32 netmask
255.255.255.0 broadcast
192.168.2.255tun0:
inet
10.0.0.1 netmask
255.255.255.255 destination
10.0.0.2tun1:
inet
10.0.1.1 netmask
255.255.255.0 destination
10.0.1.1