Fix for site-to-site OpenVPN on ubiquiti unifi routers.md ..
@@ 1,46 1,56 @@
# Fix for site-to-site OpenVPN on ubiquiti unifi routers
-
# Background:
+
# Background
I found that ubiquiti unifi routers break site-to-site by always using the [nathack](https://community.openvpn.net/Pages/NatHack) on the client side network. I got my hands on one and made a workaround which I am documenting here.
-
# The problem:
+
# The problem
All traffic from the lan to a target over the VPN gets nat’ed to the IP of the vpn client on the router. Even after I fixed that it was also not forwarding traffic from the VPN to the LAN.
-
# The fix:
+
# The fix
I was able to find the rule that causes the NAT and I was able to find where to insert a rule to allow forwarding from VPN to lan. The harder part was persistence. iptables rules do not persist a reboot, or even an openvpn reconnection. I found a directory named /data/ that can persist my scripts. I found that crontab works but does not persist reboots. I found that if I manually add a service it DOES persist reboots. By chaining this information together I was able to build a persistent fix for this router.
-
# How to fix:
+
# How to fix
On the router enable sshd and log in as root to the router over sshd.
run:
-
`mkdir /data/openvpn
+
+
```
+
mkdir /data/openvpn`
vi /data/openvpn/undo_nathack.sh
-
`
+
```
+
type i to enter insert mode and paste this:
-
`#!/bin/bash
+
```
+
#!/bin/bash
if /usr/sbin/iptables-save | /bin/grep tunovpn | /bin/grep -q MASQUERADE ;then