Looks like if I don't add OpenVPN as an interface, and enable it, clients won't be able to surf the internet.
After adding and enabling it as an interface, it appears under the firewall rules; now there are two items for OpenVPN, one is the usual interface rules and the other is the OpenVPN.
The interface is just enabled with the rest untouched (no address, no dhcp etc as openvpn has it by default).
Various documents recommend adding openvpn as an interface for the ease of applying rules, but isn't there already the OpenVPN section where rules can be applied?
Any thought?
Thanks
			
			
			
				Perhaps for services like DNS to bind to the VPN interface ???
			
			
			
				Just an update for myself,
On the way to create a 2nd OpenVPN server for a different network, suddenly realized the OpenVPN rules may apply to all servers. If I create interfaces for each server, they can then have different sets of rules.