Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    OpenVPN Client Schedules

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      d90
      last edited by

      Hello all. This is my first post here. My apologies in case this topic has been covered. I was unable to find it after searching.

      I have deployed a pfsense box on an old pc for personal use. Eventually I would like to deploy pfsense boxes at my office and satellite offices. Before doing this though, I need to iron out vpn scheduling. I want to create access schedule rules based on user\group, but I have had no luck in figuring it out. Any help would be greatly appreciated!

      ~Nick

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        You can set up schedules in Firewall > Schedules and use it in firewall rules after. But there is no way to apply firewall rules to specific user groups directly.

        A workaround is to set up a separate vpn server for each user group with its own CA and different tunnel networks and use these in rules. Or you can use "client specific overrides" to assign particular clients predefined IP addresses, which can be grouped to small subnets per user group and used in rules.

        1 Reply Last reply Reply Quote 0
        • KOMK Offline
          KOM
          last edited by

          Or you can use "client specific overrides" to assign particular clients predefined IP addresses, which can be grouped to small subnets per user group and used in rules.

          That's what I do.  Assign static IPs to the VPN users and then craft my rules to allow access only to specific resources based on the user's IP.

          1 Reply Last reply Reply Quote 0
          • D Offline
            d90
            last edited by

            viragomann, I figured I might have to do something along those lines. Thank you for taking the time to respond.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.