Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Openvpn Gateway

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann
      last edited by

      Yes, it should work that way. However, you have to put up these rules to the top, at least above of the source = 'LAN net' rule.
      The rules are checked from the top to the bottom of the rule set. If one matches it is applied and others are ignored.

      S 1 Reply Last reply Reply Quote 0
      • S
        snellie1972 @viragomann
        last edited by

        @viragomann

        I think that the problem is that I use one box with one IP address and want to switch the use off the gateway depending on the iptv connection that I use
        So it will not work yet do I have to make a special nat rule too ??

        Thanks in advance !!

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by

          That's hokey! That works with only one source IP as well as long as the destination addresses are different.

          The criteria for applying a rule are IP version, protocol, source address, source port, destination address and destination port. If any of these doesn't match, the rule will not be applied and pfSense checks the next one.

          So put your rules in the correct order and it will work as expected.

          1 Reply Last reply Reply Quote 0
          • S
            snellie1972
            last edited by

            Thank you I look in to it further

            Greets snellie

            1 Reply Last reply Reply Quote 0
            • S
              snellie1972
              last edited by

              What am I doing wrong I have created aliases with destinations address but the rules are not working!
              625D00D4-B4B1-40A0-9076-415B7C7D5CA6.png

              Thanks snellie

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                Do you have some floating rules defined?

                Also consider that you have to reset states if of the IPTVs after moving around the rules, otherwise that doesn't influence already existing connections.

                1 Reply Last reply Reply Quote 0
                • S
                  snellie1972
                  last edited by

                  Hi,

                  And no I have no floating rules and also I reset the states everytime I tried but nothing works.

                  Greetz snellie

                  1 Reply Last reply Reply Quote 0
                  • V
                    viragomann
                    last edited by

                    That's really strange. You VPN connections are up both?

                    What's happening exactly? Go the IPTVs out the WAN or do the fail?

                    1 Reply Last reply Reply Quote 0
                    • S
                      snellie1972
                      last edited by

                      Goodmorning,

                      The rules are not being read so the connections uses the default wan it is indeed very strange

                      Thanks Snellie

                      1 Reply Last reply Reply Quote 0
                      • V
                        viragomann
                        last edited by

                        Did you reset the states or restart pfSense as suggested above?

                        1 Reply Last reply Reply Quote 0
                        • S
                          snellie1972
                          last edited by

                          Yes I did it al:-)

                          1 Reply Last reply Reply Quote 0
                          • S
                            snellie1972
                            last edited by

                            BEDA0D28-FC2D-400F-9C74-0B8BB297399E.png

                            1 Reply Last reply Reply Quote 0
                            • S
                              snellie1972
                              last edited by

                              This rule works but without destination so for all vpn connections it will use the same gateway

                              NlVPN rule
                              61EA4E7D-C81D-4CDB-A77E-FA71542C069F.png

                              It looks like he Will not read the rules 192.168.1.25 with a destinations host

                              Thank in advance

                              Snellie

                              1 Reply Last reply Reply Quote 0
                              • V
                                viragomann
                                last edited by

                                And your VPN gateways are up?

                                You can check System > Advanced > Miscellaneous > Skip rules when gateway is down to aviod skipping the rules when the gateways are down.

                                For investigating I'd enable logging in all your rules and check the firewall log after to find out, which rule is applied for the upstream packets.

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  snellie1972 @viragomann
                                  last edited by

                                  @viragomann

                                  Hi thank you for your anwser i know that every vpn connection use it own interface.

                                  What i did was making a rule destination based so the destination for one iptv connection i use the gateway vpn France and the iptv one vpn Dutch.
                                  I was expecting that when i use ons iptv connection it will use the vpn France gateway and the other ons the Dutch vpn gateway but this wil not Work.
                                  Thank you i will check that

                                  Greetz snelllie

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    snellie1972
                                    last edited by

                                    Hi,

                                    The gateways are up and running so that is not the problem

                                    Greetings snellie

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.