Kuidas määrata VPN-kliendi juurdepääsuks kaugele VPN-serverile?

VPN-klient on lõppseade või tarkvara, mida kasutatakse turvalise ühenduse loomiseks kasutaja ja VPN-serveri vahel.

Mida on VPN?

VPN (Virtual Private Network) aitab teil tunneltehnoloogia abil kaugelt, turvaliselt ja privaatselt internetiressurssidele ligi pääseda. VPN krüpteerib teie isikuandmed ja varjab teie IP-aadressi avalikkuse eest, kui kasutate internetti. VPN-i kasutajate jaoks näeb see välja, nagu oleksid arvutid omavahel otse ühendatud.

Üldine võrgutopoloogia:

Sealt võtame näitena WR2100.

Sepp 1: Avatakse veebilehitseja ja minnakse veebilehele http://cudy.net või http://192.168.10.1.

Detailide saamiseks vaadake Kuidas sisse logida Cudy Routeri veebiliidesesse?

Sepp 2: Klõpsake Üldised seaded->VPN ja lubage VPN.

Vaikimisi reegel: Luba kõigile seadmetele või Kõikidele seadmetele VPN-i kasutamine keelata.

Süsteemi olek-> seadmed->seadmed->VPN lubamiseks või keelamiseks.

Site-to-Site: Võimaldab kahe saidi seadmetel omavahel suhelda.

VPN-poliitika:

Katkestatud: Ei mingeid täiendavaid seadeid.

VPN kill switch: Katkestab internetiühenduse, kui VPN-ühendus on kadunud.

Domeen: Määrake, millised domeenid lähevad läbi VPN-i ja millised mitte

Remote Subnet: Määrake, millised alamvõrgud lähevad läbi VPN-i ja millised mitte

Sepp 3: Valige Protokoll nimekirjast see, mida vajate, ja sisestage oma VPN-teenuse pakkuja poolt antud VPN-teave.

- PPTP VPN

Sisestage VPN serveri aadress (näiteks 113.92.73.163) ning VPN kasutajanimi ja parool, mille teie VPN teenusepakkuja on andnud.

- L2TP VPN

Sisestage VPN serveri aadress (näiteks 113.92.73.163), VPN kasutajanimi ja parool ning teie VPN teenusepakkuja poolt antud eeljaotatud võti.

Kui teie VPN-teenusepakkuja annab teile ka tunneli IP, mis on seotud kontoga, saate lubada valiku Kasutage kohandatud tunneli IP-d.

- OpenVPN

Klikkige Browser, et importida oma VPN teenusepakkuja poolt pakutud konfiguratsioonifail.

- WireGuard VPN

Klikkige Browser, et importida oma VPN teenusepakkuja poolt pakutud konfiguratsioonifail.

Sinterneti Interface ja Peer sünkroniseeritakse automaatselt teie VPN teenusepakkuja CONF failist.

- ZeroTier Slave

Tabele ZeroTier Network ID ja Gateway, mille ZeroTier Master on andnud. Gateway on leitav VPN Status osast.

Väline artikkel: Kuidas Cudy marsruuteriga Zerotieri kaudu kaugühendust luua?-Cudy Home

Back to blog

186 comments

@Dear Felice,
Please enable the VPN kill switch function, Then all the traffics from the clients will go through VPN connection.

“Hi,
I am using a Cudy AX3000 router configured as an OpenVPN client (ExpressVPN).
I have observed the following behavior:

The router itself connects correctly to the VPN and gets an IP in the VPN country. However, LAN clients do not appear to have their DNS traffic routed through the VPN tunnel by default. DNS queries from LAN clients are resolved via the WAN interface unless additional workarounds are implemented.
I would like to clarify:

1. Does the OpenVPN client on this router support full-tunnel routing for all LAN devices (i.e. all traffic, including DNS, forced through the VPN interface)?
2. Is there a setting to ensure DNS queries from LAN clients are always routed through the VPN tunnel and not via the WAN?
3. Does the “VPN kill switch” function enforce routing of LAN traffic through the VPN, or only block traffic when the VPN is down?
4. Are there firmware versions or models that support proper policy-based routing (e.g. select devices or all LAN traffic via VPN)?

My goal is to have all LAN devices fully routed through the VPN, including DNS, without relying on external DNS proxies or additional devices.

Thank you for your support."

Support

Hi,
I am using a Cudy AX3000 router configured as an OpenVPN client (ExpressVPN).
I have observed the following behavior:

The router itself connects correctly to the VPN and gets an IP in the VPN country. However, LAN clients do not appear to have their DNS traffic routed through the VPN tunnel by default. DNS queries from LAN clients are resolved via the WAN interface unless additional workarounds are implemented.

I would like to clarify:

1. Does the OpenVPN client on this router support full-tunnel routing for all LAN devices (i.e. all traffic, including DNS, forced through the VPN interface)?
2. Is there a setting to ensure DNS queries from LAN clients are always routed through the VPN tunnel and not via the WAN?
3. Does the “VPN kill switch” function enforce routing of LAN traffic through the VPN, or only block traffic when the VPN is down?
4. Are there firmware versions or models that support proper policy-based routing (e.g. select devices or all LAN traffic via VPN)?

My goal is to have all LAN devices fully routed through the VPN, including DNS, without relying on external DNS proxies or additional devices.

Thank you for your support.

Felice

@Dear Rado,

Is it L2TP or L2TP over IPSec? Is there a preshared key?

“I have a AC1200 Wireless mini VPN router.
I would like to setup l2tp VPN via double NATed.
Is there a way how to setup rightID? As currently VPN is failing on IDir ‘’ does not match to ’’”

“I have a AC1200 Wireless mini VPN router.
I would like to setup l2tp VPN via double NATed.
Is there a way how to setup rightID? As currently VPN is failing on IDir ‘’ does not match to ’’”

Support

I have a AC1200 Wireless mini VPN router.
I would like to setup l2tp VPN via double NATed.
Is there a way how to setup rightID? As currently VPN is failing on IDir ‘’ does not match to ’’

Rado

@Dear bledad,
You can open and edit the OpenVPN file and delete this “group nogroup”.
Then upload it to the router again.
“hello , i have error with openvpn
Sun Mar 8 07:43:17 2026 daemon.err openvpn(client)29373: Options error: Unrecognized option or missing or extra parameter(s) in /etc/openvpn/client/client.ovpn:62: gro (2.5.2)
line 62 > group nogroup
I’m stuck
please help
thank”

Support

Leave a comment