Multiple OpenVPN client connections to multiple VLANs

  • I'm looking for a way to have multiple OpenVPN client connections map to their own VLAN. Basically I need this:

    OpenVPN1 - - -  VLAN1000
    OpenVPN2 - - -  VLAN1001
    OpenVPN3 - - -  VLAN1002
    OpenVPN10 - - -  VLAN1009

    Or something like that. I will need if the VPN is down that no traffic leaves that network. Is this something that pfsense can do? If so what would be the best way to accomplish this?

  • LAYER 8 Netgate

    Yes pfSense can do that.  Follow one of the many examples regarding routing specific traffic out an OpenVPN client connection and blocking egress at WAN if the VPN is down.

    Repeat 10 times.

  • Also worth issuing a cert to each user, this way you can tell when they have been hacked if someone else attempts to connect, and also having short cert lives which you keep issuing, timescales before expiring depend on what you need for extra piece of mind.

Log in to reply