안녕하세요.
아래 2137번 질문 글때문에 계속 테스트 하고 있습니다.
카페 와서 openvpn연결을 하고 tracert로 경로를 찍어 보니
8.8.8.8나 DNS ip 기타 공개된 도메인이나 ip는 정상적으로 vpn을 통해서 나가는데,
유독 저희 회사 대표 공인ip만 vpn을 통하지 않고 카페의 게이트웨이로 나가고 있는걸 확인 했는데,
회사 대표ip도 vpn을 통해서 나가게 해야 될거 같은데, 그럴려고 하면 어떻게 해야 될까요??
조언좀 부탁 드립니다.
위 스크린샷이 회사 공인ip로 연결되어 있는 도메인으로 확인한 경로 입니다. 1번 홉의 172.16.100.1 카페의 게이트웨이 입니다.
그리고 아래는 kt dns 서버 ip와 구글 dns서버 ip로 확인한 경로 이고, 1번 홉의 10.8.0.1이 vpn의 게이트웨이 입니다.
아래는 지금 연결하고 있는 openvpn 클라이언트 설정 파일 내용 입니다.
인증키 내용은 제외 했습니다.
======================================================
dev tun
tls-client
remote aaa.aaa.dev 2194
# The "float" tells OpenVPN to accept authenticated packets from any address,
# not only the address which was specified in the --remote option.
# This is useful when you are connecting to a peer which holds a dynamic address
# such as a dial-in user or DHCP client.
# (Please refer to the manual of OpenVPN for more information.)
float
# If redirect-gateway is enabled, the client will redirect it's
# default network gateway through the VPN.
# It means the VPN connection will firstly connect to the VPN Server
# and then to the internet.
# (Please refer to the manual of OpenVPN for more information.)
redirect-gateway def1
# dhcp-option DNS: To set primary domain name server address.
# Repeat this option to set secondary DNS server addresses.
#dhcp-option DNS DNS_IP_ADDRESS
pull
# If you want to connect by Server's IPv6 address, you should use
# "proto udp6" in UDP mode or "proto tcp6-client" in TCP mode
proto udp
script-security 2
comp-lzo
reneg-sec 0
# Clients running OpenVPN 2.4 and higher will automatically upgrade from AES-256-CBC to AES-256-GCM without any configuration changes.
cipher AES-256-CBC
auth SHA512
SELECT COUNT(DISTINCT `wr_parent`) AS `cnt` FROM g4_write_network WHERE ((INSTR(wr_subject, '컴�0���0�')>0) and (INSTR(wr_subject, '모�0�0��')>0) and (INSTR(wr_subject, '�치')>0) )
Illegal mix of collations (utf8mb3_general_ci,IMPLICIT) and (euckr_korean_ci,COERCIBLE) for operation 'locate' : 1267
ϴ ̰ͺ Ȯغ
Ȥ Ư ̽ صа ƴ ǽɵdz
===========================================================================
Ȱ :
Ʈũ Ʈũ ũ Ʈ ̽ Ʈ
0.0.0.0 0.0.0.0 172.16.100.1 172.16.100.26 35
0.0.0.0 128.0.0.0 10.8.0.5 10.8.0.6 281
10.8.0.0 255.255.255.0 10.8.0.5 10.8.0.6 281
10.8.0.1 255.255.255.255 10.8.0.5 10.8.0.6 281
10.8.0.4 255.255.255.252 10.8.0.6 281
10.8.0.6 255.255.255.255 10.8.0.6 281
10.8.0.7 255.255.255.255 10.8.0.6 281
112.xxx.xxx.xxx 255.255.255.255 172.16.100.1 172.16.100.26 291
127.0.0.0 255.0.0.0 127.0.0.1 331
127.0.0.1 255.255.255.255 127.0.0.1 331
127.255.255.255 255.255.255.255 127.0.0.1 331
128.0.0.0 128.0.0.0 10.8.0.5 10.8.0.6 281
172.16.100.0 255.255.254.0 172.16.100.26 291
172.16.100.26 255.255.255.255 172.16.100.26 291
172.16.101.255 255.255.255.255 172.16.100.26 291
192.168.10.0 255.255.255.0 10.8.0.5 10.8.0.6 281
224.0.0.0 240.0.0.0 127.0.0.1 331
224.0.0.0 240.0.0.0 10.8.0.6 281
224.0.0.0 240.0.0.0 172.16.100.26 291
255.255.255.255 255.255.255.255 127.0.0.1 331
255.255.255.255 255.255.255.255 10.8.0.6 281
255.255.255.255 255.255.255.255 172.16.100.26 291
===========================================================================
:
route ôµ...
112.xxx.xxx.xxx 255.255.255.255 172.16.100.1 172.16.100.26 291
κж Ǵ° ... ̺ ɷ ؼ ǵ帮 ʾҴµ ִ ڽϴ...
ٵ ִ° ״ κ ...
ovpn redirect-gateway def1 Ʈ vpn °ŷ ˰ ִµ ߸ ˰ ִ ǰ???
ovpn route 112.xxx.xxx.xxx ؾ Ǵ Ȥ ˷ֽø ϰڽϴ.
Ȥ ִ ִٸ ϴ ߰
ּҸ route ovpn ϵڵϼ
ٽ Ȯؼ route 2 Ǹ ʿѰ ּ
route 112.219.116.190 255.255.255.255
ϽŴ ̷ ߰ ߽ϴ.
ٽ route print غ
112.xxx.xxx.xxx 255.255.255.255 172.16.100.1 172.16.100.26 291
112.xxx.xxx.xxx 255.255.255.255 10.8.0.9 10.8.0.10 281
̷ ΰ ־,
112.xxx.xxx.xxx 255.255.255.255 172.16.100.1 172.16.100.26 291
̰ ߽ϴ.
ٵ ͳ ʳ... ... ̰...
ϵ GW Ǵµ ͳ Ǵ° ̻ϳ
DNS óϴ°, ƴϸ ׳ ܺο route ãư° Ȯκ غ
ʿ ּҿ ʴ 0.0.0.0 ó Ǿϰ, Ѵٰ ͳ Ǵ°͵ ̻ϳ
openVPN ƴ ٸ VPN client ߿ 缳 ǰ ƴ VPN ʰ ϴ ִ.
dns ּ naver Ϲ Ʈ ѹ Ȯ .
ȸip ΰ̻ žմϴ.