• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall Rules not working

Scheduled Pinned Locked Moved Firewalling
22 Posts 2 Posters 1.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Y
    yupq6wlc79ts
    last edited by yupq6wlc79ts Dec 25, 2018, 4:57 AM Dec 25, 2018, 12:00 AM

    Hello,

    I have below setup allowing a single device access via WAN Gateway (non-VPN), all others via VPN Gateway only. The issue is, my single device doesn't get the internet connection at all after this setup: (please let me know if you need more information on the setup). My idea is to have couple of devices go through the non-VPN gateway, how can I achieve this?

    0_1545696011600_Firewall-Rules-LAN.png

    K 1 Reply Last reply Dec 25, 2018, 7:43 AM Reply Quote 0
    • K
      Konstanti @yupq6wlc79ts
      last edited by Dec 25, 2018, 7:43 AM

      @yupq6wlc79ts Hey
      See my rules
      The order of the rules is important
      I hope the picture will help you to understand how to do it

      0_1545723787799_a873bba8-dd3d-4448-9d8b-3a26485344f5-image.png

      1 Reply Last reply Reply Quote 0
      • Y
        yupq6wlc79ts
        last edited by Dec 25, 2018, 2:40 PM

        Thank you for your reply, but can you please elaborate on your answer?

        K 1 Reply Last reply Dec 25, 2018, 2:43 PM Reply Quote 0
        • K
          Konstanti @yupq6wlc79ts
          last edited by Konstanti Dec 25, 2018, 2:44 PM Dec 25, 2018, 2:43 PM

          @yupq6wlc79ts said in Firewall Rules not working:

          Thank you for your reply, but can you please elaborate on your answer?

          I showed you an example of how you can implement what you need
          When part of the traffic goes to the tunnel and the other uses the default gateway

          1 Reply Last reply Reply Quote 0
          • Y
            yupq6wlc79ts
            last edited by yupq6wlc79ts Dec 25, 2018, 2:44 PM Dec 25, 2018, 2:44 PM

            Looks somewhat similar to what I already did, trying to figure out what I did wrong there!

            Also, it would have helped to understand "What you did".

            K 1 Reply Last reply Dec 25, 2018, 2:47 PM Reply Quote 0
            • K
              Konstanti @yupq6wlc79ts
              last edited by Konstanti Dec 25, 2018, 2:54 PM Dec 25, 2018, 2:47 PM

              @yupq6wlc79ts said in Firewall Rules not working:

              Looks somewhat similar to what I already did, trying to figure out what I did wrong there!
              Also, it would have helped to understand "What you did".

              Can you explain what needs to be implemented ?
              What ip addresses should use the default gateway or use a VPN ?
              What traffic should not get into the tunnel ?
              What I see now from You is that all IPv4 traffic from Lan Net goes to the Internet through the NORDVPN gateway.

              1 Reply Last reply Reply Quote 0
              • Y
                yupq6wlc79ts
                last edited by Dec 25, 2018, 2:57 PM

                Sure.

                Can you explain what needs to be implemented ?

                I have three Gateways:

                WAN - Only 5 specific devices should go via WAN.
                (Default Gateway) VPN-IPv4 - All devices should go via VPN IPv4
                VPN-IPv6 - Disabled

                What ip addresses should use the default gateway or use a VPN ?

                All devices should use default gateway VPN-IPv4, expect 5 devices which I want to send via WAN.

                What traffic should not get into the tunnel ?

                Not sure.

                What I see now from You is that all IPv4 traffic from Lan Net goes to the Internet through the NORDVPN gateway.

                Yes. That's correct, all IPv4 traffic goes to Lan Net to Internet via NORDVPN. All I want now is, 5 specific devices should go directly to the internet without VPN.

                So I started with 1 example of 192.168.1.253, and selected WAN_DHCP as a gateway. I don't get any internet via this rule, so I disabled it for now (screenshot). How can I achieve this?

                K 1 Reply Last reply Dec 25, 2018, 3:02 PM Reply Quote 0
                • K
                  Konstanti @yupq6wlc79ts
                  last edited by Konstanti Dec 25, 2018, 3:12 PM Dec 25, 2018, 3:02 PM

                  @yupq6wlc79ts
                  Rules for 5 devices must be first
                  and the last one should be the rule for NORDVPN

                  A deny rule for IPv6 does not need
                  0_1545750689648_2aeef13d-2193-4e40-88ec-6c204cb1abe8-image.png

                  1 Reply Last reply Reply Quote 0
                  • Y
                    yupq6wlc79ts
                    last edited by Dec 25, 2018, 3:13 PM

                    That's exactly how I setup my 1 device to test the rule but when I do this, I don't get any internet connection on my single device. That's the issue.

                    0_1545750762300_Firewall-Rules-LAN.png

                    K 1 Reply Last reply Dec 25, 2018, 3:15 PM Reply Quote 0
                    • K
                      Konstanti @yupq6wlc79ts
                      last edited by Konstanti Dec 25, 2018, 3:15 PM Dec 25, 2018, 3:15 PM

                      @yupq6wlc79ts
                      I understand your problem.
                      NORDVPN - OPENVPN ?

                      1 Reply Last reply Reply Quote 0
                      • Y
                        yupq6wlc79ts
                        last edited by Dec 25, 2018, 3:16 PM

                        Yes, OpenVPN.

                        (sorry for late reply, since I am a new user with no reputation, I have to wait 120 seconds before I can reply, lol)

                        K 1 Reply Last reply Dec 25, 2018, 3:18 PM Reply Quote 0
                        • K
                          Konstanti @yupq6wlc79ts
                          last edited by Konstanti Dec 25, 2018, 3:20 PM Dec 25, 2018, 3:18 PM

                          @yupq6wlc79ts
                          NordVpn Openvpn client setting
                          Check this option

                          0_1545751042363_b7aef87c-8d9d-42fa-83fb-6188aa62e0a4-image.png

                          1 Reply Last reply Reply Quote 0
                          • Y
                            yupq6wlc79ts
                            last edited by Dec 25, 2018, 3:21 PM

                            It wasn't checked. I checked it and tested the device by enabling the rule, No Internet on that device.

                            K 1 Reply Last reply Dec 25, 2018, 3:22 PM Reply Quote 0
                            • K
                              Konstanti @yupq6wlc79ts
                              last edited by Konstanti Dec 25, 2018, 3:31 PM Dec 25, 2018, 3:22 PM

                              This post is deleted!
                              1 Reply Last reply Reply Quote 0
                              • Y
                                yupq6wlc79ts
                                last edited by Dec 25, 2018, 3:29 PM

                                0_1545751773900_Screenshot from 2018-12-25 09-25-02.png

                                K 1 Reply Last reply Dec 25, 2018, 3:31 PM Reply Quote 0
                                • K
                                  Konstanti @yupq6wlc79ts
                                  last edited by Konstanti Dec 25, 2018, 3:32 PM Dec 25, 2018, 3:31 PM

                                  @yupq6wlc79ts
                                  all right now.
                                  check nat / outbound for wan interface
                                  0_1545751927509_56e731d7-694f-4179-a10d-15926003de4c-image.png

                                  1 Reply Last reply Reply Quote 0
                                  • Y
                                    yupq6wlc79ts
                                    last edited by Dec 25, 2018, 3:33 PM

                                    0_1545751994300_nat outbound.png

                                    K 1 Reply Last reply Dec 25, 2018, 3:34 PM Reply Quote 0
                                    • K
                                      Konstanti @yupq6wlc79ts
                                      last edited by Konstanti Dec 25, 2018, 3:35 PM Dec 25, 2018, 3:34 PM

                                      @yupq6wlc79ts
                                      Here is and mistake
                                      no nat rule for wan 192.168.1.0/24
                                      It is necessary to add

                                      1 Reply Last reply Reply Quote 0
                                      • Y
                                        yupq6wlc79ts
                                        last edited by Dec 25, 2018, 3:36 PM

                                        The reason was, It kinda acts as a kill switch. If the VPN goes down, no devices will be able to connect to the internet.

                                        But my 5 devices aren't on VPN, so they should still be connected. What do I need to add/change here?

                                        K 1 Reply Last reply Dec 25, 2018, 3:39 PM Reply Quote 0
                                        • K
                                          Konstanti @yupq6wlc79ts
                                          last edited by Konstanti Dec 25, 2018, 3:43 PM Dec 25, 2018, 3:39 PM

                                          @yupq6wlc79ts
                                          Add a nat outbound rule for the 192.168.1.0/24 on the wan interface as I showed in the picture
                                          and 5 devices will be able to access the Internet via wan
                                          Do not delete anything

                                          1 Reply Last reply Reply Quote 1
                                          20 out of 22
                                          • First post
                                            20/22
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received