Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block mobile openvpn connection when already connected to local network

    Scheduled Pinned Locked Moved OpenVPN
    9 Posts 4 Posters 639 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      M0L50N
      last edited by

      Hi,

      I need to know if there's a way to avoid a user to connect to mobile openvpn client when his laptop is already connected to our LAN in the office? That cause me some double entries in my DNS server and other network problem.

      Thanks for any suggestions!

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @M0L50N
        last edited by

        @m0l50n

        Perhaps you could create a rule that blocks OpenVPN from connecting from the local LAN.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        M 1 Reply Last reply Reply Quote 1
        • M
          M0L50N @JKnott
          last edited by

          @jknott :) simple like that. I dont know why I didn't think about that! I was searching an option in openVPN!! :)

          Thanks!

          A 1 Reply Last reply Reply Quote 0
          • A
            akuma1x @M0L50N
            last edited by

            @m0l50n said in How to block mobile openvpn connection when already connected to local network:

            @jknott :) simple like that. I dont know why I didn't think about that! I was searching an option in openVPN!! :)

            Thanks!

            So, did it work? I would like to setup something similar to what you're trying to do. I've got mobile (laptop) users that do the same thing, while in the office on the trusted wireless LAN network... :(

            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @akuma1x
              last edited by

              @akuma1x

              Does it connect automagically? In both Linux and Windows, I have to manually enable the VPN. Regardless, it should be easy enough for you to try.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              A 1 Reply Last reply Reply Quote 0
              • A
                akuma1x @JKnott
                last edited by

                @jknott No, not automatically. The laptop machines have an OpenVPN program that launches at startup, the user has to manually click the "connect" button. From being out of the office for a year, some of them are still thinking that they have to click the button, even while they are physically sitting at their desk in the office.

                JKnottJ 1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by Rico

                  I feel you, IT support would be so nice without the Users...doing weird things all day long you could never think about. ;-)
                  A firewall rule to block traffic hitting your OpenVPN server from the LAN interface works just fine here.

                  -Rico

                  1 Reply Last reply Reply Quote 0
                  • JKnottJ
                    JKnott @akuma1x
                    last edited by

                    @akuma1x

                    At work, a couple of years ago, I came across something similar. For some reason, several people thought they had to connect to the guest WiFi, instead of the regular WiFi and then VPN in. This was before the pandemic though.

                    PfSense running on Qotom mini PC
                    i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                    UniFi AC-Lite access point

                    I haven't lost my mind. It's around here...somewhere...

                    1 Reply Last reply Reply Quote 0
                    • M
                      M0L50N
                      last edited by

                      Effectively, in It support we always have to use imagination for different solution for the dumbest users! :)

                      I've didn't implement and test the solution, but I'm sur it will works!!!

                      Thanks all and have a good day!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.