Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1.2.3RC1: Filtering rules on OpenVPN interface

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      Guest
      last edited by

      Hello,

      I've established a PKI-Based OpenVPN Site-To-Site Tunnel between two locations without any hassle.

      Having upgraded to 1.2.3-RC1, I'm trying to add firewall rules on the tun0 interface
      that I added in 'Interfaces'.

      I've disabled 'Disabled all auto-added VPN rules' in 'System->Advanced'.

      My new rule also appears when using 'pfctl -sr | grep tun0'
      (block drop in quick on tun0 inet proto icmp all label "prohibit ping")

      Why can I still ping fom the 'client' to the OpenVPN Server?
      Do I need to restart the tunnel, when rules change?

      It does seem that no rule is honored on tun0, I do not understand why that is the case.
      Also, I did not find a clear answer in this forum.

      I'd appreciate any help, thanks a lot,

      • Karl
      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        It seems it simply takes a minute or two for the rule to apply but it does work.
        Is this lag plausible?
        (I'm using soekris 5501 boxes with HW Crypto)

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          Did you clear the statetable after changing the rules?
          Also it can take some time for the rules to reload.
          (click on the "monitor" link after pressing the "apply rules" button to see when the rules are completely reloaded.)

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • ?
            Guest
            last edited by

            i think it simply it takes a while to reload the ruleset, i used monitoring.

            thanks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.