On the server: # iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE Client and server configuration is exactly the same, except that the server has this extra line: push "redirect-gateway local def1"