@@ -5,5 +5,5 @@ RUN apk add --no-cache openvpn
VOLUME /hackthebox
WORKDIR /hackthebox
-CMD ["openvpn", "--config", "/hackthebox/vpn-config.ovpn", \
+COPY ./vpn.sh /vpn.sh
- "--user", "openvpn", "--group", "openvpn"]
+CMD ["/vpn.sh"]
@@ -0,0 +1,11 @@
+#!/bin/sh
+
+set -ex
+iptables -P FORWARD DROP
+iptables -A FORWARD -i eth0 -o tun0 -d 10.10.10.0/24 -j ACCEPT
+iptables -A FORWARD -i tun0 -o eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
+iptables -t nat -A POSTROUTING -o tun0 -j MASQUERADE
+openvpn --config /hackthebox/vpn-config.ovpn \
+ --user openvpn --group openvpn