Routing everything except a certain IP range through an OpenVPN tunnel

Posted on


I’ve been working with my OpenVPN server for a while, and I have a rather interesting problem. I need to redirect all client traffic through the tunnel except for a couple IP’s that need to be resolvable locally. The way I’m doing this is pushing these routes from the server:

Server ‘PUSH’ directives

 push "redirect-gateway def1 bypass-dhcp" 
 push "dhcp-option DNS" 
 push "dhcp-option DNS"

I’m seeing that translating into these Windows routes:

Windows routes occurring

Wed Aug 31 15:14:35 2011 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS,dhcp-option DNS,route,topology net30,ping 5,ping-restart 30,ifconfig'
Wed Aug 31 15:14:35 2011 ROUTE default_gateway=

Wed Aug 31 15:14:40 2011 C:WINDOWSsystem32route.exe ADD 199.[*.*.*] MASK
Wed Aug 31 15:14:40 2011 C:WINDOWSsystem32route.exe ADD MASK
Wed Aug 31 15:14:40 2011 C:WINDOWSsystem32route.exe ADD MASK
Wed Aug 31 15:14:40 2011 C:WINDOWSsystem32route.exe ADD MASK

I’ve hidden my server’s IP beginning with 199 for security purposes.

What I’ve gathered

I’m assuming that is a kind of code for “everything,” so I’m not sure how I could get this to work, but the general idea is that I need a specific IP range (172.16.*) to be resolvable on the LOCAL NETWORK (of the client) meaning it does not go through the VPN tunnel and the client can connect to 172.16.* locally.

Is this possible? Routes can be executed through the command line, server “push” or client config options. Any way to get this to work while still routing other traffic through would do, really.

Additional Info

I have the server running on Debian 64-bit and the client running on Windows 7 (although Vista needs to work as well).

Client/server configs can be provided if needed.


It appears as if after doing some more research, based on grawity’s answer that more specific routes will take precedence, after the server’s PUSH i can simply do a

--route [ip to bypass] net_gateway

net_gateway as defined in the ‘route’ directive in the openvpn man page will resolve to the pre-existing ip default gateway

Simply add another route, and it will take precedence over less-specific ones:

172.16.* translates to with netmask

route add mask if index

where index is the index of your LAN network interface as shown by route print. For example, 0x3 or similar.

Leave a Reply

Your email address will not be published. Required fields are marked *