Opened 4 years ago

Closed 4 years ago

Last modified 4 years ago

#692 closed Feature Wish (worksforme)

OpenVPN should have a --nopull option to generically reject pushed options

Reported by: pdbogen Owned by:
Priority: minor Milestone:
Component: Configuration Version: OpenVPN 2.3.11 (Community Ed)
Severity: Not set (select this one, unless your'e a OpenVPN developer) Keywords:


Currently there's only (as far as I can tell) route-nopull, which rejects a predefined set of options.

This functionality should be extended and generalized so that route-nopull becomes an alias for --nopull <some options>; and --nopull is exposed as a setting that can generically reject pushed options.

Change History (4)

comment:1 Changed 4 years ago by Steffan Karger

Resolution: worksforme
Status: newclosed

Just don't specify pull, if you don't want to pull. In practice this means that instead of client you just put tls-client in your config file. See the man-page:

       A  helper  directive  designed  to simplify the configuration of
       OpenVPN's client mode.  This directive is equivalent to:


comment:2 Changed 4 years ago by Gert Döring

First, what syzzer said - if you don't want pull, do not config pull :-)

Then, there is the nice feature added via trac #682 - git master (which will become 2.4.0 later this year) has "pull-filter" which can be used to selectively accept/ignore/reject individual parts of the pushed option list.

comment:3 Changed 4 years ago by Eric Crist

Just for posterity, I'll provide a bit more clarification.

First off, the --client configuration option is actually a macro of multiple options:

If you specify --tls-client directly, you can simply omit the --pull option from the list. Effectively, this will serve as your --nopull request in this ticket.

Typically, users want to pull most configuration directives from the server, with the exception of the routing table. For that, we offer the --route-no-pull configuration directive. This can be used in conjunction with --client. As cron2 has stated, there is a new feature added in #682 which effectively allows the client to omit or filter specific routing table entries to provide more granularity.

comment:4 Changed 4 years ago by pdbogen

I think the pull-filter upcoming is 2.4.0 is exactly what I want; thanks guys! (I do want to pull, just not everything- and what I want to block isn't routes.)

Note: See TracTickets for help on using tickets.