
118
12.9.4 OpenVPN 1:1 NAT
For the net-to-net part, the OpenVPN server LAN network and the OpenVPN client LAN
network are different. But some time, the LAN network will be same for both sides.
When this situation occurred, the routing rules will be ambiguous that will result in the PC1 and
the PC2 can't communicate each other. Thus, the router OpenVPN provides the 1:1 NAT
feature. The feature will convert the conflict subnet to different subnet. In this case, you can use
1:1 NAT feature to convert the OpenVPN server and client side LAN network.
For the OpenVPN server side, we fill up the Network be
192.168.10.0
and Netmask
255.255.255.0
. The setting will make the router convert the OpenVPN server side LAN network
from
192.168.1.0/24
to
192.168.10.0/24
when the VPN traffic is coming.
For the OpenVPN client side, same as server side but we fill up the Network as
192.168.11.0
.
The setting will make router convert the OpenVPN client side LAN network from
192.168.1.0/24
to
192.168.11.0/24
when the VPN traffic is coming.
LTE Router
OpenVPN client
LTE Router
OpenVPN Server
PC2: 192.168.1.2/24
PC1: 192.168.1.2/24
LAN: 192.168.1.1/24
src: 192.168.1.2
dst: 192.168.10.2
src: 192.168.11.2
dst: 192.168.10.2
WAN: 172.168.1.2/24
WAN: 172.168.1.1/24
1:1 NAT
1:1 NAT
src: 192.168.11.2
dst: 192.168.1.2
LAN: 192.168.1.1/24
www.e-rake.us.com