Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Client Access To WAN Port

    Firewalling
    2
    7
    481
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      urbnsr
      last edited by urbnsr

      Hello,

      I am trying to figure out a setup where an OpenVPN client can access a specific server on the LAN while allowing same client access to the WAN port to pass general traffic through our pfSense firewall.

      My firewall rule(s) either allow access to both WAN and all LAN by specifying "all" for destination or access just to our target local server. If I write a rule to limit access to one server on the LAN, a earlier rule written for "WAN net" destination access does not allow general traffic to the OVPN client.

      Can I reach my goal (this way)? Thanks!

      Untitled.png

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @urbnsr
        last edited by

        @urbnsr said in OpenVPN Access To WAN Port:

        WAN port to pass general traffic through our pfSense firewall.

        Wan net would just be that Wan network - if your say wanting to let your clients route through pfsense to get to 8.8.8.8 for example - wan net wouldn't do that you would have to setup your rules to allow the internet, which is really a any rule. You can place block rules before the any rule to keep them from going where you don't want them to go.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        U 1 Reply Last reply Reply Quote 0
        • U
          urbnsr @johnpoz
          last edited by

          @johnpoz Thanks for your reply.

          This seems to work in limited testing. What about:

          Untitled2.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @urbnsr
            last edited by

            @urbnsr yeah that can work, but not a fan of ! rules. I would do a specific block to lan net before you allow a any rule if I was doing it.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            U 1 Reply Last reply Reply Quote 0
            • U
              urbnsr @johnpoz
              last edited by

              @johnpoz Maybe like this (Only way I could make my goal work):

              Untitled3.png

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @urbnsr
                last edited by

                @urbnsr yeah if your going to block lan directly, then you no longer need the ! rule, can just be any for destination. Because your explicitly blocking access to lan..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                U 1 Reply Last reply Reply Quote 0
                • U
                  urbnsr @johnpoz
                  last edited by

                  @johnpoz Oh, yeah. !! Thanks.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.