Access internet with activated openVPN

  • hi, i have a simple configuration as you can see in the Picture. i want to configure Firewalls so that when openVPN active is, user1 has Access to user2 and to Internet as well, but when openVPN down is, there must be no Access to both user2 and Internet.

    Access to user2 works now with activated openVPN but the Problem is user1 has always Access to Internet.
    i tried different Firewall rules but no success. can someone advise me how to do it.


