|
From: James Y. <ji...@yo...> - 2004-05-14 18:18:13
|
Doug Lytle <su...@dr...> said: > Frank Elsner wrote: > > >I'm surprised, but will test as time permits over the weekend. > > > >Surprised because http://openvpn.sourceforge.net/man.html#lbAR says: > > > >| You can use any address you wish for the tunnel endpoints but make sure > >| that they are private addresses (such as those that begin with 10 or > >| 192.168) and that they are not part of any existing subnet on the networks of > >| either peer. If you use an address that is part of your local subnet for > >| either of the tunnel endpoints, you will get a weird feedback loop. > > This would be correct if you were using tap devices. I probably wrote that snippet before a lot of people started using OpenVPN to make ethernet bridges. That statement should be modified because the "not part of any existing subnet" isn't really true when bridging. James |