The most common OpenVPN deployment scenario is letting remote users
access the server's LAN (office/home network). This requires:
1. net.ipv4.ip_forward=1
2. iptables MASQUERADE on the LAN-facing interface
3. push 'route <LAN-net>' so clients know to send LAN traffic through VPN
Previously this was only mentioned in the FAQ row 'ping不通服务端',
with no actionable instructions. Users (including the project's own
first deployment) hit this exact issue and had to figure it out from
forum posts.
Changes:
README.md:
- New section 'IP 转发与内网访问' before 防火墙与公网暴露
- Covers: enabling ip_forward (immediate + persistent via sysctl.d),
MASQUERADE rules for one/multiple LAN interfaces, push routes,
verification commands, troubleshooting table, full checklist
- FAQ table: add explicit row for 'gateway reachable, LAN not'
- Features table: add '内网转发' row
- TOC: link new section
scripts/install.sh:
- Auto-enable ip_forward on install (idempotent, persistent via
/etc/sysctl.d/99-openvpn-manager.conf)
- Skip silently in containerized environments (no /proc/sys write)
- Print reminder about manual MASQUERADE rule with link to docs