Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Site-to-Site restrict Site A from accessing something on Site B

    OpenVPN
    1
    2
    281
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vinneo last edited by

      Site A:
      Interfaces: WAN, LAN (10.1.0.0/24), VPN, OpenVPN
      Client: 10.1.0.1/24;

      Site B:
      Interfaces: WAN, LAN (10.2.0.0/24), VPN, OpenVPN
      Server: 10.2.0.1/24;

      I want to block Client 10.1.0.1 from accessing Server 10.2.0.1, how can I do this without adding any firewall rules to Site A? My problem is I don't understand the difference between the default OpenVPN interface of pfsense, and the custom interface if you add the ovpnc1? I though traffic from Site A will arrive at Site B in the "VPN (ovpnc1)" interface and I can block it there but It goes straight to LAN.




      1 Reply Last reply Reply Quote 0
      • V
        vinneo last edited by

        Update:
        Okay, I got this far that firewall rules added to the default OpenVPN interface work (i.e. drop all traffic from client 10.1.0.1 on Site B firewall), but if I add the same rule to the ovpnc1 (VPN) interface nothing happens. What is the purpose of adding ovpnc1 if firewall rules applied to it don't work?

        1 Reply Last reply Reply Quote 0
        • First post
          Last post

        Products

        • Platform Overview
        • TNSR
        • pfSense Plus
        • Appliances

        Services

        • Training
        • Professional Services

        Support

        • Subscription Plans
        • Contact Support
        • Product Lifecycle
        • Documentation

        News

        • Media Coverage
        • Press
        • Events

        Resources

        • Blog
        • FAQ
        • Find a Partner
        • Resource Library
        • Security Information

        Company

        • About Us
        • Careers
        • Partners
        • Contact Us
        • Legal
        Our Mission

        We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

        Subscribe to our Newsletter

        Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

        © 2021 Rubicon Communications, LLC | Privacy Policy