<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[SOLVED] per user rules]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I successfully configured my pfSense with the new traffic filtering function. I would like to have different rules depending of the openVPN user.<br />
I believe that could be done by forcing a specific IP address based upon the CN found in the client certificate. The rules would apply based upon this IP address. Is that the right thing to do?<br />
This can apparently done in the Client-specific configuration page. However I'm not sure about what to put here. My openVPN address is 192.168.100.0/24 and my LAN is 192.168.0.0/24. Can you help me with those settings?</p>
<p dir="auto"><strong>Interface IP</strong><br />
Set this option to push an IP to the client's interface. Expressed as a CIDR range (e.g. 10.5.0.0/16). The first IP in the range will be used as the remote IP of the interface, and the second IP will be used as the local IP of the interface.</p>
<p dir="auto"><strong>Custom options</strong><br />
You can put your own custom options here, separated by semi-colons (;). They'll be added to the client-specific configuration.</p>
<p dir="auto">Thank you<br />
Alphazo</p>
]]></description><link>https://forum.netgate.com/topic/20149/solved-per-user-rules</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 22:26:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/20149.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 22 Dec 2009 17:36:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [SOLVED] per user rules on Tue, 22 Dec 2009 18:02:21 GMT]]></title><description><![CDATA[<p dir="auto">Nice.. thank you very much. When I put 192.168.100.8/30 in the client config, I was able to set filtering rules for the IP 192.168.100.9.</p>
]]></description><link>https://forum.netgate.com/post/217214</link><guid isPermaLink="true">https://forum.netgate.com/post/217214</guid><dc:creator><![CDATA[alphazo]]></dc:creator><pubDate>Tue, 22 Dec 2009 18:02:21 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED] per user rules on Tue, 22 Dec 2009 17:51:34 GMT]]></title><description><![CDATA[<p dir="auto">You have to put exactly what it tells you:<br />
If 192.168.100.0/24 is your OpenVPN subnet, then the first client will need 192.168.100.4/30, the second 192.168.100.8/30, etc.</p>
]]></description><link>https://forum.netgate.com/post/217210</link><guid isPermaLink="true">https://forum.netgate.com/post/217210</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Tue, 22 Dec 2009 17:51:34 GMT</pubDate></item></channel></rss>