OVPN client separation using IP and FW rules
-
We have a number of OVPN users that we wish to control access to resources
Each user is being allocated an IP which works
Using the assigned IP we use FW rules to limit what they can and cannot access
Is this a secure way to control access?
-
@McMurphy said in OVPN client separation using IP and FW rules:
Using the assigned IP we use FW rules to limit what they can and cannot access
I assume, you have already configured Client Specific Overrides for each user, which assign them a certain IP each and configured your filter rules with these IPs.
Is this a secure way to control access?
If you did this it is secure.
-
The client IPs are being assigned in FreeRadius.
One place to setup a user as opposed to both FreeRadius and then CSO. The IPs are being assigned correctly so I expect the outcome is the same as if I was using CSOs