@Pippin:
I know OpenVPN has a built in internal packet filter that would allow firewalling client-to-client connections
Here I'm confusing tun and tap. In case of tap above is true.
With a pf_plugin_module for OpenVPN one could setup a scheme for who can talk to who.
1. Does allowing "Inter-client communication" in "Servers–>Edit server" set the client-to-client option in server config?
2. If so, then this cannot be firewalled?
Yes, I just checked this, it does set client-to-client in server config and to my knowledge it cannot be firewalled.
Is that true also for pfSense?
If so, then maybe this should be stated under the tick box/help.
It would mean, if one wants to firewall client-to-client communication, do not tick this box.