From 380c0bb2981093bb23d85eeca29e5b214de5e14a Mon Sep 17 00:00:00 2001 From: Ian Kelling <ian@iankelling.org> Date: Mon, 23 Jan 2017 22:24:56 -0800 Subject: [PATCH] minor rename and improvements --- vpn-server-setup | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/vpn-server-setup b/vpn-server-setup index 8d25c1f..4dcb215 100755 --- a/vpn-server-setup +++ b/vpn-server-setup @@ -83,7 +83,11 @@ teeu /etc/openvpn/server.conf <<'EOF' cipher aes-256-cbc # Be the default gateway for clients. push "redirect-gateway def1" +# just sets up the ability to have client specific configs +client-config-dir /etc/openvpn/client-config EOF +mkdir -p /etc/openvpn/client-config + if $dns; then # Be the dns server for clients @@ -101,7 +105,7 @@ EOF gw=$(ip route | sed -rn 's/^default via .* dev (\S+).*/\1/p') -sudo dd of=/etc/systemd/system/mynat.service <<EOF +sudo dd of=/etc/systemd/system/vpnnat.service <<EOF [Unit] Description=Turns on nat iptables setting @@ -112,10 +116,10 @@ ExecStart=/sbin/iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o $gw -j MASQUERA ExecStop=/sbin/iptables -t nat -D POSTROUTING -s 10.8.0.0/24 -o $gw -j MASQUERADE [Install] -WantedBy=multi-user.target +WantedBy=openvpn.service EOF systemctl daemon-reload # needed if the file was already there -systemctl enable mynat.service -systemctl start mynat.service +systemctl enable vpnnat.service +systemctl start vpnnat.service systemctl restart openvpn@server -- 2.30.2