Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RESOLVED : Firewall rules and OpenVPN client Vs. default gateway

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cookiedelu
      last edited by

      Hello everyone,

      I'm trying for hours to configure a strict rule allowing a LAN IP to pass by an OpenVPN client connection configured on the firewall and block that IP to use the default gateway when the OpenVPN client is unavailable. None of my tests works.
      I'm sometimes having the OpenVPN service down and so the traffic pass by the default gateway. I simply want the traffic to pass by the OpenVPN client ONLY and clearly block this traffic to pass by the default gateway.
      Rules or floating rules, I can't get lead of this.

      Did anyone experience this behavior and found a solution ? Or is it just impossible ?

      Thanks

      Cookie

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        Try System: Advanced: Miscellaneous - Skip rules when gateway is down
        "By default, when a rule has a specific gateway set, and this gateway is down, rule is created and traffic is sent to default gateway.This option overrides that behavior and the rule is not created when gateway is down."
        I think checking the box will stop the system from being "nice" and failing the traffic over to the default gateway.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • C
          cookiedelu
          last edited by

          Yes, after several tests, this option did the trick!

          Thank you. I feel to have now my traffic under control :)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.