External VPN access to LE box behind FW...

  • awiouy I begging you now for help! ;) I know you mastered all those things as I've seen your posts from years back about tinc...

    After couple days ofr esting from it I'm back with new ideas :)

    Managed to get my own config like you said using "$DIR_LEGACY" in your tinc.start

    So far so good. I'm connected and vpn ip works (can browse

    Need to add my home subnet and if possible have my home ip address as main mobile ip.

    Here is my tinc.conf


    ifconfig $INTERFACE netmask


    ip addr del dev $INTERFACE
    ip link set $INTERFACE down



    Subnet =
    Subnet =
    Ed25519PublicKey = =================================
    Port = 11443
    HTPC:~ # ip route
    default via dev eth0 dev tun0 scope link src dev docker0 scope link src dev br-cb2fc26669fb scope link src dev eth0 scope link src dev eth0 scope link

    Edited once, last by Borygo77 ().

  • I do not understand your configuration. Why do you use two subnets?

    It has been a long time that I have not played with tinc, but I remember that it was complicated.

    Some advice:

    - on LibreELEC, use an interface name that is blacklisted by connman, eg vmnet_foo, to prevent connman from messing with its configuration,

    - by default interfaces on LibreELEC will not forward traffic, so you have to enable ip forwarding (for tinc in router mode) or promiscuitous mode (for tinc in switch mode),

    - use two addresses of your home network for the tinc interfaces (home ip with a route to remote, remote ip with a route to via

    - I vaguely remember static routes on the router and/or brutils.

    It will therefore probably be easier to configure a device more suitable to your purpose than a LibreELEC mediacenter


  • Everything I was reading always said to not make vpn subnets same as host subnet is or you will get in troubles? ;)

    And it actually doesn't work when I change setup to and subnet

    Got also tp-link 1043v1 but it'll be too weak to serve any files for me I'm afraid :(

    My htpc old machine with x86 arch is working for me as emby server and is quite doing nothing so why not to give it another life ? ;)

    It was quite loud in living room so I switched to amlogic as my players connected to htpc....

    Think all I miss id some route from network to but I'm so lost with linux that I got no idea how to add it :(

    This is friend of mine OpenVPN server on strong machine

    Kernel IP routing table
    Destination Gateway Genmask Flags Metric Ref Use Iface
    default _gateway UG 0 0 0 enp1s0 U 0 0 0 tun0 U 0 0 0 enp1s0

    And this is how mine looks like

    Kernel IP routing table
    Destination Gateway Genmask Flags Metric Ref Use Iface
    default fritz.box UG 0 0 0 eth0 * U 0 0 0 tun0 * U 0 0 0 eth0 * UH 0 0 0 eth0

    And my proper iptables

    Edited 3 times, last by Borygo77 ().

  • Unless you bridge your devices, the tinc subnet should be different from the lan subnet. It can be a subnet of the lan subnet or a different subnet. Traffic must somehow be routed: you can add a route in your dhcp server for that.


  • So what would be best? I might try do same Subnet as my home Subnet is for vpn and try bridge eth0 with tun0.

    I don't think I can add static routes in Fritzbox which I got from my network provider. Again. Would like to have my openwrt as main router but this won't serve 1gbps connection ;)

    I'm really thankful that you answering all my question but I'm feeling really dumb speaking about networks, bridges and forwardings.. 😳

    edit; I do actually found this just now 😁

    Configuring a static IP route in the FRITZ!Box | FRITZ!Box 4040 | AVM International

    Might try this first....

  • If you really can't route, then configure tinc in switch mode and set both the network and tinc devices of LibreELEC in promisc mode. You might even not need routes (just if the arp tables are propagated.


  • All sorted! If anyone is looking for help I can provide full support with configs to get full tunel working :)

    Thank you awiouy! :)

    Edited once, last by Borygo77: sorted! ().