OPNsense Forum

English Forums => Virtual private networks => Topic started by: Andreas.Wien on November 29, 2022, 07:26:49 PM

Title: VPN with WAN fallback
Post by: Andreas.Wien on November 29, 2022, 07:26:49 PM
The usecases I find here force traffic through a VPN and block unencrypted WAN traffic.
I intend to implement a different policy:
primarily I want to use the VPN, and only as a failover the traffic can use plain WAN.
however: Tier1 (VPN) has not priority, traffic is routed unencrypted out the WAN, even if WAN is set to never in the group.
According to the Firewall.Log Files.Live View the "(alias)-Traffic goes through VPN" rule is applied to pass the trafic.

Help's appreciated! What am I missing here?
Title: Re: VPN with WAN fallback
Post by: Andreas.Wien on November 30, 2022, 01:20:49 AM
I don't understand in which order the various mechanisms, even if they work as I believe, decide to which gateway the packet is routed:
and what's the correct settings for a WAN and VPN gateway xactly?
I assume that, if I punch no holes, i.e. allow rules @Firewall.Rules.OpenVPN I'm safe from attacks that originate in the VPN network?
Title: Re: VPN with WAN fallback
Post by: Andreas.Wien on December 02, 2022, 05:34:11 PM
works4me since the update to Version 22.7.9