Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Restrict one user to only one internal vlan

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 3 Posters 371 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • frogF
      frog
      last edited by

      We have a client who has 5 internal vlans (vlan interfaces configured on the PFSENSE) with staff using openvpn to access things remotely via freeradius.

      The customer wants to give their Telco supplier vpn access to only the phone vlan. Is that possible and if so how?

      thanks.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @frog
        last edited by

        @frog In the vpn config set it up so the vpn client gets a specific IP, then in the vpn rules only allow that client access to the phone vlan.

        https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configure-overrides.html#client-specific-overrides

        Or another way without a specific client override is setup a 2nd instance of openvpn, say on a different port say 1195 vs default 1194, use a different tunnel network for this instance.. Now anyone connecting to this instance, your phone support supplier can be set in the openvpn firewall rules to only have access to your phone vlan

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        frogF D 2 Replies Last reply Reply Quote 0
        • frogF
          frog @johnpoz
          last edited by frog

          @johnpoz thanks that was exactly what I was thinking. how do you setup the client to get a specific ip?

          DOH you've given me the link. I'll check there thanks.* but I'm using freeraadius will that matter?

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @frog
            last edited by

            @frog said in Restrict one user to only one internal vlan:

            but I'm using freeraadius will that matter?

            no

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • D
              dlogan @johnpoz
              last edited by

              @johnpoz This is the way

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.