Per-user firewall rules with OpenVPN
I'm running pfSense 2.0/amd64, the Oct 4 snapshot.
I have two groups of VPN users. One group should have a very liberal set of firewall rules, while the other should have very restrictive firewall rules. Is this possible with pfSense's OpenVPN? I can't find a way to define different groups of VPN users in a useful way.
Any suggestions would be appreciated.
you could create two servers one for each vpn group and specify two different ports. that way you can apply different rules to each.
You can also setup CSC entries for the CNs of the certificates being used to connect, force them to a specific IP addressed, and then firewall those addresses as normal. An alias containing all of the members of a given group would be helpful.
As shadowadepts said though, two separate instances would work as well. You might even want to make sure they use separate CAs if you do not use any other form of auth (e.g. TLS+Local User Auth)