• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Policybased routing and Openvpn

Scheduled Pinned Locked Moved OpenVPN
3 Posts 2 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    smurfb
    last edited by Feb 28, 2007, 2:41 PM

    Hi again.

    New troubles and cant find the solution on the forum.

    I have two WAN. One for internal company network which is assigned to the WAN interface. And the other one (the internet) is assigned to OPT1.

    Everything is fine, I use policybased routing for webproxy on DMZ to reach internet.

    But how do I make Openvpn send it replys to the OPT1/internet gateway and not the defaultroute WAN interface? This is for road warriors.

    I have tried to add to OPT1 the sourceadress/sourceport (carp adress) of Openvpn (port 9000) and OPT1 as gateway. But it doesnt work, any other ideas?

    Cheers,
    Joel

    1 Reply Last reply Reply Quote 0
    • H
      hoba
      last edited by Feb 28, 2007, 3:54 PM

      Make sure you have a firewallrule on top of you rules to pass traffic to the remote openvpn IPs through the default gateway to prevent these from being directly balanced/routed to the pools. This is required for IPSEC as well if you use  multiwan.

      1 Reply Last reply Reply Quote 0
      • S
        smurfb
        last edited by Mar 1, 2007, 3:21 PM

        I solved it by making a NAT-rule from OPT2 interface to the same with another port, and all packages goes back the same way. Ugly hack but it works.

        Couldnt get the policybased routing to work with Openvpn, works great with everything else.

        1 Reply Last reply Reply Quote 0
        2 out of 3
        • First post
          2/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received