Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Add rules to OpenVPN client interface?

    Firewalling
    3
    9
    633
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sporkme
      last edited by

      How does one implement rules on an openvpn client interface?

      I went to Interfaces -> Assign and selected/enabled the ovpnc interface of interest, and I now see a rules tab for it in the firewall config section.  I've restarted the vpn connection.  Even with no rules (which is a default block), traffic flows without restriction in both directions.

      How do I attach rules to this?

      1 Reply Last reply Reply Quote 0
      • G
        GoldFish
        last edited by

        A picture of rules might help

        • pfSense Enthusiast *
        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Rules on the OpenVPN tab are processed first.

          If those rules match or block traffic the interface rules are never reached.

          If you want the assigned interface rules to be controlling, delete/disable all of the rules on the OpenVPN tab.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • S
            sporkme
            last edited by

            @GoldFish:

            A picture of rules might help

            As I said above, there are no rules on this interface, so it should be a default deny/drop.

            Anyhow, pics of that and the interface assignments attached.

            ![screenshot-dt 2018-01-27 at 1.24.18 PM.png](/public/imported_attachments/1/screenshot-dt 2018-01-27 at 1.24.18 PM.png)
            ![screenshot-dt 2018-01-27 at 1.24.18 PM.png_thumb](/public/imported_attachments/1/screenshot-dt 2018-01-27 at 1.24.18 PM.png_thumb)
            ![screenshot-dt 2018-01-27 at 1.24.46 PM.png](/public/imported_attachments/1/screenshot-dt 2018-01-27 at 1.24.46 PM.png)
            ![screenshot-dt 2018-01-27 at 1.24.46 PM.png_thumb](/public/imported_attachments/1/screenshot-dt 2018-01-27 at 1.24.46 PM.png_thumb)

            1 Reply Last reply Reply Quote 0
            • G
              GoldFish
              last edited by

              What are the rules in OPENVPN tab?

              • pfSense Enthusiast *
              1 Reply Last reply Reply Quote 0
              • S
                sporkme
                last edited by

                @Derelict:

                Rules on the OpenVPN tab are processed first.

                If those rules match or block traffic the interface rules are never reached.

                If you want the assigned interface rules to be controlling, delete/disable all of the rules on the OpenVPN tab.

                This is intriguing, but isn't that tab only for the OpenVPN server, not the client instances?

                I mean, if I remove the rules on that tab, where do I put rules for the server instance?

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  I mean, if I remove the rules on that tab, where do I put rules for the server instance?

                  On the assigned interface for the client or server.

                  This is intriguing, but isn't that tab only for the OpenVPN server, not the client instances?

                  That tab is an interface group of all OpenVPN instances on the node. Both clients and servers.

                  I say again:

                  Rules on the OpenVPN tab are processed first.

                  If those rules match or block traffic the interface rules are never reached.

                  If you want the assigned interface rules to be controlling, delete/disable all of the rules on the OpenVPN tab.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • S
                    sporkme
                    last edited by

                    @Derelict:

                    I mean, if I remove the rules on that tab, where do I put rules for the server instance?

                    On the assigned interface for the client or server.

                    This is intriguing, but isn't that tab only for the OpenVPN server, not the client instances?

                    That tab is an interface group of all OpenVPN instances on the node. Both clients and servers.

                    I say again:

                    Rules on the OpenVPN tab are processed first.

                    If those rules match or block traffic the interface rules are never reached.

                    If you want the assigned interface rules to be controlling, delete/disable all of the rules on the OpenVPN tab.

                    I know you keep saying, but consider perhaps your understanding is incorrect.

                    Right now there's a pass all rule on the OpenVPN server interface.  I have added a "log packets matching…" checkbox on this rule.  There is traffic passing over the OpenVPN client interfaces.  It is not being logged.  Explain why no traffic matches if that rule overrides the client rules (which are still empty, which should be a deny all).

                    Also what sense would it make to have interface rules for each client instance if the rules have no effect?

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Demanding much?

                      Post both sets of rules. OpenVPN tab and the assigned interface.

                      Describe specifically what is the client and what is the server and what specific traffic you think is misbehaving. Details, like specific addresses and ports.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.