OPNsense Forum

English Forums => Virtual private networks => Topic started by: ns on October 07, 2022, 10:41:13 AM

Title: How to add a firewall rule based on a wireguard interface
Post by: ns on October 07, 2022, 10:41:13 AM
The firewall rule interface drop down menu allows to select the different physical interfaces, "IPSec", but does not allow to match on a wireguard interface.

From the shell I can see that there is a wg1 interface, so in theory opnsense could match on it.

My use case: I want to whitelist access to specific ports from the connected VPN (road warrior) clients to other devices opnsense is connected to.
Title: Re: How to add a firewall rule based on a wireguard interface
Post by: Patrick M. Hausen on October 07, 2022, 12:09:51 PM
Go to Interfaces > Assignments and create an e.g. WG1 there. Then you can use the WireGuard interface in rules.