• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Issues with Firewall rules on openVPN Interface

Scheduled Pinned Locked Moved Firewalling
2 Posts 2 Posters 102 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    PelikanDo
    last edited by Apr 24, 2020, 7:53 PM

    Hi,

    I am having trouble with my firewall rules on my openVPN interface.

    I created an openVPN Server and added an interface for this server so that I could add different rules for each server. The rules should provide connections to all needed network services (DNS, NTP, some MS DC stuff,...).

    However when monitoring the Client Traffic, i cannot see any returning packets like DNS responses, just outbound traffic.

    I created a "block all" rule at the bottom to log the traffic that would be blocked anyway, however all connections seem to work. The state table also validates this as there are states for my client. However the logging on my "pass" rules does not log anything.

    When using a default allow any traffic rule, everything is working like it should.

    What am I missing in the Rule Settings?

    I also tried using the "interface net" setting as the source address.

    To explain my screenshot:

    dnsServers is an alias pointing on 2 aliases (samba0_DMZ & nas0_DMZ) as well as to FQDNs

    dnsServices is an alias representing the ports 53 and 853

    ntpServers is pointing on my local ntp-Server over its FQDN

    samba0_DMZ is pointing on the IPv4 of the server with the possibillity to add the IPv6

    nas0_DMY does the same thing except for nas0
    VPN Firewall Rules.PNG

    1 Reply Last reply Reply Quote 0
    • R
      Rico LAYER 8 Rebel Alliance
      last edited by Rico Apr 25, 2020, 3:07 PM Apr 25, 2020, 3:06 PM

      Firewall Rule processing is:

      1. Floating Tab
      2. Group Tabs (OpenVPN for example)
      3. Interface Tabs

      So if you have any-any on your OpenVPN group tab traffic will never hit the OpenVPN Interface.
      Which Interface is your screenshot showing?

      -Rico

      1 Reply Last reply Reply Quote 0
      1 out of 2
      • First post
        1/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received