Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I want to force the client to use its own internet gateway.

    OpenVPN
    3
    4
    206
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      selcuk_ks
      last edited by

      I want to force the client to use its own internet gateway. In my scenario, the client must definitely use its own internet. Some clients can send all traffic over VPN and the internet can be accessed through the VPN server's internet. I prevent this situation with security rules, but this time the internet cannot be accessed in any way. Even if routing is done to access the internet via VPN, my VPN server must not allow this and force it to use its own gateway. How do I do this?

      V P 2 Replies Last reply Reply Quote 0
      • V
        viragomann @selcuk_ks
        last edited by

        @selcuk_ks
        You VPN server do not have much impact on the clients routing table.
        You can push routes to the clients though, but this is nothing more than a recommendation in the end.

        So on the server just block any unwanted traffic from the client.

        Also you need an outbound NAT rule on WAN for the tunnel pool to masquerade the traffic with your WAN address. Without this, no internet access would be possible for the VPN clients.

        If pfSense has created the outbound NAT rule automatically, you can switch to hybrid mode and add a rule for the tunnel network and disable NAT inside it.

        S 1 Reply Last reply Reply Quote 1
        • S
          selcuk_ks @viragomann
          last edited by

          @viragomann Thanks. I will try this when I have free time.

          1 Reply Last reply Reply Quote 0
          • P
            pwood999 @selcuk_ks
            last edited by

            @selcuk_ks Do you mean force general internet traffic out the clients local gateway, and only all VPN for services you host ?
            If so, this is standard split tunnel, so un-select the "Force all traffic through tunnel" option

            c2ef77b5-4e3b-4919-9504-7d2d4e23d0a3-image.png

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.