Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    strict firewall rules on OpenVPN

    Firewalling
    4
    6
    519
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lon Townsend
      last edited by

      I am following documentation, in regards to tightening down my VPN, using point to point, configuration. I added rules on the OpenVPN tab from server lan to client lan, on my client firewall, and did the reverse on my server firewall. When i disabled the all OpenVPN rule, that the documentation says to normally create, my traffic wouldn't cross the VPN. Tunnel was still active, but my rules locked me out of other firewall. Was there anything else I needed to do? Maybe rebooting firewall in order for new rules to take affect?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        huh? So you blocked access, and your wondering why you can not pass the traffic?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        L 1 Reply Last reply Reply Quote 0
        • L
          Lon Townsend @johnpoz
          last edited by

          @johnpoz I know what i did, but how do i limit the traffic going across the VPN? I want to tighten it down for only one network. I understand that the tunnel connects two networks together, but is there a way to limit the type of traffic across it. We only really use it to make IP phones believe they are internal yet allowing clients to have their own network, separate from another network.

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            So what exactly is your actual problem/question? How to only allow connections from your phones in location A to the PBX in location B?
            The easy way in a nutshell:
            Add some alias containing all your phone IPs, use it in a Firewall Rule as Source with Destination your PBX.

            Later you can go crazy only allowing specific protocols/ports if you want...

            -Rico

            L 1 Reply Last reply Reply Quote 0
            • L
              Lon Townsend @Rico
              last edited by

              @Rico I think I have actually done that on the VPN server side by adding the WAN interface of the client, to the rule on the server side. Basically saying only allow traffic from this WAN interface to access the server WAN across port 1200. Its the OpenVPN rule, from client to server that isn't doing anything. The ALLOW ALL rule, on the OpenVPN tab is doing everything.

              1 Reply Last reply Reply Quote 0
              • G
                glark Banned
                last edited by glark

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.