• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] Re: How to block traffic when VPN is down

Scheduled Pinned Locked Moved OpenVPN
3 Posts 2 Posters 4.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    CaretakersCurse
    last edited by Aug 3, 2016, 12:23 AM Jul 27, 2016, 11:28 PM

    I have an OpenVPN Connection that I only want one or two clients forwarded into, I also need a kill switch if the VPN goes down…

    Reading this post gets me like 95% of the way where I want to go but is old and missing photos.

    The client (right now just my cellphone for testing), works fine when the vpn is on. IPLeak shows I've got everything good when the vpn is up. Once I disable the VPN (via Status>OpenVPN) the client gets sent back into the WAN.

    I do not want this, I need the client to be blocked if the VPN is down.

    So far, this is what my firewall rules look like (-100.152 is the client I need behind the VPN w/ killswitch):

    Floating:
    http://i.imgur.com/4XqGKhn.png
    WAN:
    http://i.imgur.com/nVbjBfs.png
    LAN:
    http://i.imgur.com/xTuxYjr.png

    What am I missing? I'm sure some of my rules are redundant or just stupid, I'm a noob.

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Aug 2, 2016, 7:17 PM

      Take the gateway off the block rule on LAN

      And System > Advanced, Miscellaneous tab, check "Skip rules when gateway is down".

      If that floating rule is to block outbound on WAN, it would never match a source of a LAN IP address, NAT has happened by then. That can also be removed.

      The block rule on the WAN tab is both incorrect (could never match anything, has a gateway set – never put gateways on block rules), and unnecessary. Remove it, too.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • C
        CaretakersCurse
        last edited by Aug 3, 2016, 12:25 AM Aug 3, 2016, 12:22 AM

        Thank you for your help, another user just PM'ed me with another method of fixing the issue.

        The killswitch now works using the link I just posted above and I'm ready to move on in my network issue 'todo' list.

        Thanks so much for you help.

        Also I had already deleted the redundant/useless rules. I had just started making any rule on whim to see if I could stumble on the solution.

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received