I went down a deep rabbit hole the last two days to get name resolution working over openvpn and after all it turned out as a problem with pihole rather than openvpn. But now I'm stuck at the last piece of the puzzle.
For some reason, the vpn tunnel is only working, if I'm running the container with host networking.
When using bridged networking as shown in the setup guide, vpn clients can connect to the server, but they can't reach any local or external hosts, neither by name, nor by ip.
I suspect, I have to do some additional routing inside the container or on the docker host, but TBH I had to fiddle around with too much networking the last two days and may not be able to see the wood for the trees anymore.
server 192.168.255.0 255.255.255.0
verb 3
key /etc/openvpn/pki/private/my.example.org.key
ca /etc/openvpn/pki/ca.crt
cert /etc/openvpn/pki/issued/my.example.org.crt
dh /etc/openvpn/pki/dh.pem
tls-crypt /etc/openvpn/pki/ta.key
key-direction 0
keepalive 10 60
persist-key
persist-tun
proto udp
# Rely on Docker to do port mapping, internally always 1194
port 1194
dev tun0
status /tmp/openvpn-status.log
user nobody
group nogroup
comp-lzo no
### Route Configurations Below
route 192.168.254.0 255.255.255.0
### Push Configurations Below
setenv opt "block-outside-dns"
push "dhcp-option DNS 192.168.4.248"
push "comp-lzo no"
I went down a deep rabbit hole the last two days to get name resolution working over openvpn and after all it turned out as a problem with pihole rather than openvpn. But now I'm stuck at the last piece of the puzzle.
For some reason, the vpn tunnel is only working, if I'm running the container with host networking.
When using bridged networking as shown in the setup guide, vpn clients can connect to the server, but they can't reach any local or external hosts, neither by name, nor by ip.
I suspect, I have to do some additional routing inside the container or on the docker host, but TBH I had to fiddle around with too much networking the last two days and may not be able to see the wood for the trees anymore.
What I'm forgetting here?
This is my current config:
ovpn_env.sh:
openvpn.conf: