How to correctly set up a cascade connection?

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
DROZD01
Posts: 14
Joined: Tue May 06, 2025 2:16 am

How to correctly set up a cascade connection?

Post by DROZD01 » Sat Oct 03, 2026 7:44 am

So here's the plan:
Clients => Server A => Server B => Internet

Both servers have public IPs, both are VPS'es
Server A already has Kea set up for handling DHCP on a created virtual TAP, with the subnet of 192.168.30.0/24 (and TAP itself seems to be 192.168.30.1), and Bind9 for DNS.
I set up cascade connection on Server A to Server B, and clients of Server A are visible through "Server Manager" app on Server B (so i assume the link has been established).
I did not set up anything on the Server B yet, other than SoftEther itself. I did create another TAP on it, and manually assigned it 192.168.30.2 address.
Right now i can ping 192.168.30.2 from a client and get a reply, and i can ping 192.168.30.1 for Server B and get a reply, but pinging 192.168.30.2 from Server A does not work.

How do should i set up Server B in order for it to route all external (not the traffic between clients on 192.168.30.0/24) traffic through it's eth0 interface?

solo
Posts: 1909
Joined: Sun Feb 14, 2021 10:31 am

Re: How to correctly set up a cascade connection?

Post by solo » Sat Oct 03, 2026 9:15 am

On B set DisableKernelModeSecureNAT = 1

To block intra-client traffic adapt VPN Gate's packet filtering rules viewtopic.php?f=7&t=68039#p97841

DROZD01
Posts: 14
Joined: Tue May 06, 2025 2:16 am

Re: How to correctly set up a cascade connection?

Post by DROZD01 » Sat Oct 03, 2026 3:53 pm

solo wrote: ↑
Sat Oct 03, 2026 9:15 am
On B set DisableKernelModeSecureNAT = 1
And what does this do? I did apply this to the Server B, but no change in behavior occured.

solo wrote: ↑
Sat Oct 03, 2026 9:15 am
To block intra-client traffic adapt VPN Gate's packet filtering rules viewtopic.php?f=7&t=68039#p97841
I don't need to block connections between clients, I just don't want them to get routed through Server B and back (if it's even something that could happen).

Maybe there's a more in-depth guide for setting up such a config somewhere?

Post Reply