<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[What&#x27;s the difference between OpenVPN and OPT4 interface?]]></title><description><![CDATA[<p dir="auto">The OpenVPN wizard creates a virtual interface for the server instance.</p>
<p dir="auto">However that interface doesn't show up in the available interfaces for the DNS server.</p>
<p dir="auto">So I created an OPT4 interface in the Interfaces/Assignment menu so that DNS would serve the VPN client network.</p>
<p dir="auto">But now in the f/w Rules menus, there's an OPT4 and an OpenVPN interface.</p>
<p dir="auto">Which is which and how should rules be divided between them?</p>
]]></description><link>https://forum.netgate.com/topic/163733/what-s-the-difference-between-openvpn-and-opt4-interface</link><generator>RSS for Node</generator><lastBuildDate>Wed, 11 Mar 2026 04:17:36 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/163733.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 13 May 2021 21:07:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:44:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> I didn't try that.  Since adding the OPT4 /ovpns1 assigned interface fixed it for me I stopped trying.  I'll go back to the config and try when it's idle.</p>
]]></description><link>https://forum.netgate.com/post/983134</link><guid isPermaLink="true">https://forum.netgate.com/post/983134</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 20:44:50 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:34:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a><br />
Did you add the tunnel network to unbound ACLs?</p>
]]></description><link>https://forum.netgate.com/post/983132</link><guid isPermaLink="true">https://forum.netgate.com/post/983132</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 14 May 2021 20:34:53 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:33:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> Ok that I understand, but then why doesn't unbound enumerate it to respond to queries?</p>
]]></description><link>https://forum.netgate.com/post/983131</link><guid isPermaLink="true">https://forum.netgate.com/post/983131</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 20:33:49 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:31:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/eric-lts">@<bdi>eric-lts</bdi></a> Correct. e.g. if the client net is 192.168.23.0/24 and local DNS is desired (so the pfBlockerNG-devel can filter DNS), I have to add the assigned interface for the DNS quieries to function.  I tried sending them to 192.168.0.1 but that wouldn't work for some reason.  If I used external DNS like 1.1.1.1 and 9.9.9.9 those would work.</p>
]]></description><link>https://forum.netgate.com/post/983130</link><guid isPermaLink="true">https://forum.netgate.com/post/983130</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 20:31:51 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:29:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a><br />
The OpenVPN tab is basically an interface group, implicitly added be pfSense, when configuring an OpenVPN instance. It includes all OpenVPN servers and clients you're running.</p>
<p dir="auto">For some special purposes interface groups cannot be used.</p>
<p dir="auto">Consider that firewall rules on interface group tabs are probed at first. So if a group rule applies to an incoming packet, the rules on the interface tab you,ve assigned to the instance will be ignored.</p>
]]></description><link>https://forum.netgate.com/post/983129</link><guid isPermaLink="true">https://forum.netgate.com/post/983129</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 14 May 2021 20:29:19 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:24:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a> So the OpenVPN client isn't able to reach your unbound server on your pfSense? I'm assuming you're providing a DNS server list to your VPN clients under the Advanced Client Settings on your OpenVPN server? What servers do you have listed there?</p>
<p dir="auto">You otherwise have rules set to allow traffic on the OpenVPN interface at least for port 53 (if you haven't changed that from the default in unbound)?</p>
]]></description><link>https://forum.netgate.com/post/983128</link><guid isPermaLink="true">https://forum.netgate.com/post/983128</guid><dc:creator><![CDATA[Eric-LTS]]></dc:creator><pubDate>Fri, 14 May 2021 20:24:23 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 20:22:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/eric-lts">@<bdi>eric-lts</bdi></a> Unless I create the ovpns1 interface then I can't get unbound to answer DNS queries on the client /24 because the OpenVPN pseudo interface doesn't show up in the interface list of the DNS Resolver page.</p>
<p dir="auto">Only creating the OPT4/ovpns1 interface allows unbound to service attached clients.</p>
]]></description><link>https://forum.netgate.com/post/983127</link><guid isPermaLink="true">https://forum.netgate.com/post/983127</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 20:22:47 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 16:58:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a> https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/assign.html</p>
<p dir="auto">I'm not 100% on why they are created separately, but it seems to be a difference between whether or not you are looking to initiate and route traffic out the VPN tunnel. When you create the OpenVPN server, you use the OpenVPN interface in the firewall rules to allow inbound traffic from the VPN clients. The new OpenVPN interface you are then able to assign and create in the Interfaces &gt; Assignments &gt; Interface Assignments window is for when you are trying to route traffic initiating from your pfSense out the VPN tunnel. For example, if you are connecting your pfSense as a client to say a NordVPN server and you want to policy route traffic to it, you would create the client config and then assign the interface and configure your Outbound NAT accordingly. You would otherwise use that interface in a peer-to-peer configuration to ensure traffic can flow bidirectionally over the tunnel.</p>
<p dir="auto">As far as I understand, the OpenVPN interface you assign is strictly to create an outbound gateway from your pfSense, and the firewall interface it assigns is strictly for inbound traffic from the OpenVPN tunnel.</p>
]]></description><link>https://forum.netgate.com/post/983075</link><guid isPermaLink="true">https://forum.netgate.com/post/983075</guid><dc:creator><![CDATA[Eric-LTS]]></dc:creator><pubDate>Fri, 14 May 2021 16:58:44 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 08:20:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kom">@<bdi>kom</bdi></a> The problem is the wizard creates an interface (OpenVPN) which is NOT in the assigned interface list it only shows up in the rules menu.</p>
<p dir="auto">Unbound doesn't see this interface.  At all.</p>
<p dir="auto">You have to create the new interface OPT4 manually for DNS to see it to work (ovpns1); now there are two interfaces.  The one the wizard created (OpenVPN) is not in the assigned interface list.</p>
]]></description><link>https://forum.netgate.com/post/982957</link><guid isPermaLink="true">https://forum.netgate.com/post/982957</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 08:20:55 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 02:41:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a> Every interface has to have at least one rule to let traffic flow.  The OpenVPN wizard will create it for you but if you manually assign an interface then you have to create it yourself.</p>
]]></description><link>https://forum.netgate.com/post/982948</link><guid isPermaLink="true">https://forum.netgate.com/post/982948</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Fri, 14 May 2021 02:41:59 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Fri, 14 May 2021 01:42:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kom">@<bdi>kom</bdi></a> That's what I figured, but unless you enable the OPT4 rule, then the DNS server can't reply to the interface.</p>
<p dir="auto">Methinks this is a structural bug as it infers two distinct classes of what an Interface is or not.</p>
]]></description><link>https://forum.netgate.com/post/982945</link><guid isPermaLink="true">https://forum.netgate.com/post/982945</guid><dc:creator><![CDATA[lohphat]]></dc:creator><pubDate>Fri, 14 May 2021 01:42:13 GMT</pubDate></item><item><title><![CDATA[Reply to What&#x27;s the difference between OpenVPN and OPT4 interface? on Thu, 13 May 2021 21:23:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/lohphat">@<bdi>lohphat</bdi></a> IIRC the OpenVPN tab is kind of a global list.  If you have your OpenVPN connection assigned to an interface then pfSense will use the interface rules.  If no interface then it uses the OpenVPN tab rules.</p>
]]></description><link>https://forum.netgate.com/post/982919</link><guid isPermaLink="true">https://forum.netgate.com/post/982919</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Thu, 13 May 2021 21:23:44 GMT</pubDate></item></channel></rss>