Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [SOLVED] Re: How to block traffic when VPN is down

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      CaretakersCurse
      last edited by

      I have an OpenVPN Connection that I only want one or two clients forwarded into, I also need a kill switch if the VPN goes down…

      Reading this post gets me like 95% of the way where I want to go but is old and missing photos.

      The client (right now just my cellphone for testing), works fine when the vpn is on. IPLeak shows I've got everything good when the vpn is up. Once I disable the VPN (via Status>OpenVPN) the client gets sent back into the WAN.

      I do not want this, I need the client to be blocked if the VPN is down.

      So far, this is what my firewall rules look like (-100.152 is the client I need behind the VPN w/ killswitch):

      Floating:
      http://i.imgur.com/4XqGKhn.png
      WAN:
      http://i.imgur.com/nVbjBfs.png
      LAN:
      http://i.imgur.com/xTuxYjr.png

      What am I missing? I'm sure some of my rules are redundant or just stupid, I'm a noob.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Take the gateway off the block rule on LAN

        And System > Advanced, Miscellaneous tab, check "Skip rules when gateway is down".

        If that floating rule is to block outbound on WAN, it would never match a source of a LAN IP address, NAT has happened by then. That can also be removed.

        The block rule on the WAN tab is both incorrect (could never match anything, has a gateway set – never put gateways on block rules), and unnecessary. Remove it, too.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • C
          CaretakersCurse
          last edited by

          Thank you for your help, another user just PM'ed me with another method of fixing the issue.

          The killswitch now works using the link I just posted above and I'm ready to move on in my network issue 'todo' list.

          Thanks so much for you help.

          Also I had already deleted the redundant/useless rules. I had just started making any rule on whim to see if I could stumble on the solution.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.