Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent Firewall with Openvpn

    Scheduled Pinned Locked Moved OpenVPN
    4 Posts 2 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      PLBarton
      last edited by

      I have searched through the forums and I cannot find an issue exactly like this one.  I hope someone is able to assist me.

      I have a single pfSense box configured in transparent firewall mode following the configuration from http://pfsense.trendchiller.com.  The WAN port is connected to an upstream router providing Internet access and the LAN port is connected to a small network of PCs.  The transparent firewall has an active OpenVPN tunnel terminated on an OpenVPN server externally located on the Internet.  From the diagnostic menu on the (pfSense) transparent firewall I can ping the IP space behind the OpenVPN server successfully verifying the connection of the tunnel.

      My dilemma is that I want the local PCs to route to the Internet through the (pfSense) transparent firewall as if it was not there, however when they attempt to reach the IP space behind the OpenVPN server then they route across the OpenVPN tunnel.

      I am assuming that I can build a firewall rule to accomplish this but I can not see a way to do it.  If anyone can point me in the right direction I would be greatly appreciative.

      1 Reply Last reply Reply Quote 0
      • Cry HavokC Offline
        Cry Havok
        last edited by

        Does the OpenVPN tunnel become the default route?

        1 Reply Last reply Reply Quote 0
        • P Offline
          PLBarton
          last edited by

          No, all traffic would continue to flow through the bridge as normal, only traffic destined for the other side of the OpenVPN tunnel would be directed through it.

          1 Reply Last reply Reply Quote 0
          • Cry HavokC Offline
            Cry Havok
            last edited by

            In theory you'll find the routing configured on the OpenVPN server will handle that.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.