Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    How is this VPN Guide

    OpenVPN
    2
    2
    488
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      it101 last edited by

      So I have been looking for a good guide to force 1 VLAN through a PIA VPN and have my standard VLAN exit normally through my ISP.

      How does this guide look? https://philsheets.me/blog/multi-vlan-vpn-endpoint-pfsense-network/

      I am in no way affiliated with this guide or the writer/creator. I just stumbled upon it through some google-fu.

      1 Reply Last reply Reply Quote 0
      • Derelict
        Derelict LAYER 8 Netgate last edited by

        The attached indicates he has no concept of what the firewall rules on an OpenVPN interface actually do. What he is telling you to do is pass any connection that ARRIVES into that OpenVPN circuit into your firewall.

        The exact opposite should be done. An OpenVPN client to a provider such as PIA should be treated as a WAN, with only specific traffic passed inbound. If you can receive port-forwarded connections at all.

        Nice of him to promote my NO_WAN_EGRESS technique, though. It's the only way to be sure.

        ![Screen Shot 2017-09-10 at 7.11.39 PM.png](/public/imported_attachments/1/Screen Shot 2017-09-10 at 7.11.39 PM.png)
        ![Screen Shot 2017-09-10 at 7.11.39 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-09-10 at 7.11.39 PM.png_thumb)

        Chattanooga, Tennessee, USA
        The pfSense Book is free of charge!
        DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • First post
          Last post