Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Per-user firewall rules with OpenVPN

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 3 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      agshekeloh
      last edited by

      Hi,

      I'm running pfSense 2.0/amd64, the Oct 4 snapshot.

      I have two groups of VPN users.  One group should have a very liberal set of firewall rules, while the other should have very restrictive firewall rules.  Is this possible with pfSense's OpenVPN?  I can't find a way to define different groups of VPN users in a useful way.

      Any suggestions would be appreciated.

      Thanks,
      ==ml

      1 Reply Last reply Reply Quote 0
      • S
        shadowadepts
        last edited by

        you could create two servers one for each vpn group and specify two different ports. that way you can apply different rules to each.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          You can also setup CSC entries for the CNs of the certificates being used to connect, force them to a specific IP addressed, and then firewall those addresses as normal. An alias containing all of the members of a given group would be helpful.

          As shadowadepts said though, two separate instances would work as well. You might even want to make sure they use separate CAs if you do not use any other form of auth (e.g. TLS+Local User Auth)

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.