<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Client Specific Overrides]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">To give different access to the network with the OpenVPN server for users , I create each time a "Client Specific Overrides" with a "tunnel network" more specific.</p>
<p dir="auto">Exemple:</p>
<p dir="auto">OpenVPN Serveur tunnel network : 192.168.100.0/24<br />
User1 : 192.168.156.64/26<br />
User2 : 192.168.156.128/26</p>
<p dir="auto">And I create specific rules for each prefix / 26 in the firewall</p>
<p dir="auto">But since I have update my pfSense, all the more specific prefixes than /25 do not work. The problem is that I can not do a lot of /25 in a /24 . Why /26 or /27 is not long working? Can not connect with OpenVPN Client</p>
<p dir="auto">thanks</p>
]]></description><link>https://forum.netgate.com/topic/104763/client-specific-overrides</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 14:40:50 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/104763.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 29 Aug 2016 21:30:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Client Specific Overrides on Mon, 29 Aug 2016 22:39:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">why would you not just give the user specific IP in your tunnel</p>
</blockquote>
<p dir="auto">Even better! But how we specify a specific IP for a user in tunnel ? Same configuration (Client Specific Overrides) with a CIDR / 32 ?</p>
]]></description><link>https://forum.netgate.com/post/646707</link><guid isPermaLink="true">https://forum.netgate.com/post/646707</guid><dc:creator><![CDATA[fabienfs]]></dc:creator><pubDate>Mon, 29 Aug 2016 22:39:10 GMT</pubDate></item><item><title><![CDATA[Reply to Client Specific Overrides on Mon, 29 Aug 2016 22:05:42 GMT]]></title><description><![CDATA[<p dir="auto">If your using client overrides why would you not just give the user specific IP in your tunnel and then make your rules based upon their IP directly why would they need a /26?  Are you wanting vpn users to be able to talk to each other while they are all connected to the vpn directly?</p>
<p dir="auto">If you want to use the /cidr in your firewall rules that fine to give a group of users access to something, etc.  A few rev back they did change the default behavior of the topology and net30, etc..</p>
<p dir="auto">https://redmine.pfsense.org/issues/5526</p>
<p dir="auto">If you were using net30 you can change it back to that..</p>
]]></description><link>https://forum.netgate.com/post/646704</link><guid isPermaLink="true">https://forum.netgate.com/post/646704</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 29 Aug 2016 22:05:42 GMT</pubDate></item></channel></rss>