Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules tab for non-assigned interface

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 2 Posters 801 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      reilos
      last edited by reilos

      Hi there,

      I seem to have a firewall rules tab for a non-assigned interface:
      0_1549105257302_Rules.jpg

      Assigned interfaces:
      0_1549105744351_Ass.jpg

      When i DO assign, enable and rename the interface to OpenVPN, i get a second tab for OpenVPN, but then with all caps:
      0_1549105865978_Rules2.jpg

      Anyone seen this before?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • RicoR Offline
        Rico LAYER 8 Rebel Alliance
        last edited by

        This is a group tab which appears after adding some OpenVPN Server or Client instance.

        -Rico

        R 1 Reply Last reply Reply Quote 0
        • R Offline
          reilos @Rico
          last edited by reilos

          @rico Thanks. Could you explain a bit more on that? What's it for? I don't have any interface group.

          Thanks

          1 Reply Last reply Reply Quote 0
          • RicoR Offline
            Rico LAYER 8 Rebel Alliance
            last edited by Rico

            In your second screenshot we see you added NordVPN as OpenVPN Client, this is why you get the OpenVPN Group tab.
            Rules placed there apply to all OpenVPN instances. In pfSense Group tabs are processed before single Interface tabs in Firewall Rules.

            -Rico

            R 1 Reply Last reply Reply Quote 0
            • R Offline
              reilos @Rico
              last edited by

              @rico Wow, i totally missed that, even though it's clearly mentioned in the documentation (even in the firewall basics) i see now. Sometimes I feel like such a noob :)

              Thanks for the quick response!

              1 Reply Last reply Reply Quote 0
              • RicoR Offline
                Rico LAYER 8 Rebel Alliance
                last edited by

                BTW even if you have the OpenVPN Group tab empty it is already doing some work for you by actively blocking all incoming requests. And this is probably what you want by default when connecting to some VPN provider. ☺

                -Rico

                1 Reply Last reply Reply Quote 0
                • R Offline
                  reilos
                  last edited by

                  I'm quite new to to VPN, just started testing some things, but is why is that blocking needed if you don't have an interface assigned?

                  Are VPN group/interface tabs more or les like the wan/lan tabs? Where you block incoming requests for the VPN on the group tab and restrict outgoing traffic on the VPN interface tab?

                  1 Reply Last reply Reply Quote 0
                  • RicoR Offline
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    Check out https://www.netgate.com/resources/videos/openvpn-as-a-wan-on-pfsense.html

                    -Rico

                    1 Reply Last reply Reply Quote 0
                    • R Offline
                      reilos
                      last edited by reilos

                      That's a great link that clarifies some things (my basic understanding in my previous comment seems correct), thanks!
                      Still wrapping my head around the parts in slide 15 & 16. When my loud kids are in bed, i'll check if the video explains that part simple enough for me :)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.