[Openswan Users] Informing about networks which are behind the VPN in split tunnel config.

Jacco de Leeuw jacco2 at dds.nl
Tue May 6 11:20:14 EDT 2008

Oguz Yilmaz wrote:

> LAN ( - SW( - VPNRouter ( ) +++ VPN Users
> Our VPN users connect and are assigned an IP from subnet by
> l2tpd. There are configured as split-tunnel. That is, they use internet
> directly not over VPNRouter.
> How can I automatically inform VPN clients about subnet
> connections should go over VPNRouter?

Well, either let l2tpd assign VPN users IP addresses from the LAN subnet
(, apparently). Or drop the split tunnelling. Or use DHCP Inform
to set a static route to on the clients.

Regarding DHCP Inform, Wolfgang "wogri" Hennerbichler has described
such a setup at http://www.wogri.at/RoadWarrior-VPN.249.0.html
There's a couple of other things that are worth mentioning but
I have not yet put them on my webpage. It's a bit hack-ish at
the moment.

> virtual_private=%v4:,%v4:,%v4:,%v4:!

You would need to exclude all your internal subnets, i.e.
add %v4:! and remove %v4:

Jacco de Leeuw                         mailto:jacco2 at dds.nl
Zaandam, The Netherlands           http://www.jacco2.dds.nl

More information about the Users mailing list