<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Multiple tun and which is which.]]></title><description><![CDATA[<p dir="auto">I've been playing with openvpn for a bit and I was happy to succeed in a site to site, and now a roadwarrior style setup also.  Now that I am up and running I am moving onto the next step of limiting traffic.  Right now I have no filtering and no assigned adapters.  Can someone point me out in the general direction as I got swamped in the seach…<br />
1.  How do I identify which tunnel is which so when I assign an adapter I know which is which?  Right now if I create opt1, I have to choose from tun0 (663) and tun1 (60480). how can I identify which is my site to site or the roadwarrior one?<br />
2.  If i currently only want port 80 traffic through the vpn, add I would have to do is set a firewall rule to allow port 80 on the opt1 adapter from opt to lan? (if I remember right all traffic is blocked and the rules overwrite?).</p>
<p dir="auto">thanks!</p>
<p dir="auto">Update.  ok I could not wait. I assigned the interface and then the interface status gave me the ip which told me which one it was.   I am at a loss on the firewall.  Do I block on the opt1 or the lan.  Seems not matter what I do, I can't block anything.  I've put a block all on the opt1 and a block opt1 on the lan rules and nothing stops traffic.  someone care to point me in the right direction....?</p>
]]></description><link>https://forum.netgate.com/topic/20275/multiple-tun-and-which-is-which</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Apr 2026 23:40:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/20275.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Dec 2009 20:56:42 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Multiple tun and which is which. on Wed, 06 Jan 2010 03:38:41 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<p dir="auto">You can set in the custom "custom option" field which tun will be assigned to which connection.<br />
See the OpenVPN man-pages on how to do that.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tester_02">@<bdi>tester_02</bdi></a>:</p>
<blockquote>
<p dir="auto">2.  If i currently only want port 80 traffic through the vpn, add I would have to do is set a firewall rule to allow port 80 on the opt1 adapter from opt to lan? (if I remember right all traffic is blocked and the rules overwrite?).</p>
</blockquote>
<p dir="auto">What exactly do you want?<br />
Allow what kind of traffic from where to where?<br />
Can you describe that and show a screenshot of the rule you already have?</p>
<p dir="auto">Thanks for support!<br />
I did figure out which vpn was which by assigning the opt and seeing which ip it was assigned.  So now I have both vpn's assigned.<br />
Opt1 is my site to site vpn, and Opt2 is my roadwarrior style.  The only setting I have on it is that I set the bridge to disabled, and I set the ip address to match my setup in the openvpn settings. <br />
  What I am a bit of a loss at is the firewall blocking.  What I want to do is just allow port 80 on my opt1.  So I just setup a rule to only allow tcp port 80, as I believe everything else is blocked by default in pfsense.  It does seem to block traffic from the other site to mine.<br />
  The problem is that I can still connect directly to other ports on the remote site.  What I am guessing is that the NAT is causing my problems?  Would I have to override the automatic outbound nat, and set it for AON.  The problem there is I am not sure about the rules..<br />
Background info..  local net 192.168.4.<em>.  Site 2 192.168.1.</em></p>
<p dir="auto">I am still a bit of a loss to all this, as I would have assumed that opt1 would block all traffic unless I open it up.  That NAT portion makes a bit of sense, but I would have originally thought the rules would override it.</p>
<p dir="auto">Any help is appreciated.</p>
]]></description><link>https://forum.netgate.com/post/218620</link><guid isPermaLink="true">https://forum.netgate.com/post/218620</guid><dc:creator><![CDATA[tester_02]]></dc:creator><pubDate>Wed, 06 Jan 2010 03:38:41 GMT</pubDate></item><item><title><![CDATA[Reply to Multiple tun and which is which. on Mon, 04 Jan 2010 14:26:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tester_02">@<bdi>tester_02</bdi></a>:</p>
<blockquote>
<p dir="auto">1.  How do I identify which tunnel is which so when I assign an adapter I know which is which?  Right now if I create opt1, I have to choose from tun0 (663) and tun1 (60480). how can I identify which is my site to site or the roadwarrior one?</p>
</blockquote>
<p dir="auto">You can set in the custom "custom option" field which tun will be assigned to which connection.<br />
See the OpenVPN man-pages on how to do that.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tester_02">@<bdi>tester_02</bdi></a>:</p>
<blockquote>
<p dir="auto">2.  If i currently only want port 80 traffic through the vpn, add I would have to do is set a firewall rule to allow port 80 on the opt1 adapter from opt to lan? (if I remember right all traffic is blocked and the rules overwrite?).</p>
</blockquote>
<p dir="auto">What exactly do you want?<br />
Allow what kind of traffic from where to where?<br />
Can you describe that and show a screenshot of the rule you already have?</p>
]]></description><link>https://forum.netgate.com/post/218411</link><guid isPermaLink="true">https://forum.netgate.com/post/218411</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Mon, 04 Jan 2010 14:26:53 GMT</pubDate></item></channel></rss>