OPNsense Forum

Archive => 19.7 Legacy Series => Topic started by: TheCodeGeek on September 13, 2019, 12:26:30 am

Title: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 13, 2019, 12:26:30 am
Hi folks,

I have a VPN service configured in OPNsense 19.7.4 and I want to use it exclusively for P2P traffic. I have an alias configured for the ports that I want to filter by. I want to block these ports from accessing my default gateway and force them to my second gateway. I want to force all other traffic to use the default gateway. I have been looking through the documentation, but the process to do this is unclear to me. Can anyone help?

Note: Currently, when the VPN is on, all traffic gets blocked (or is passed to the VPN and it's not working). The only way to gain access to the internet is to turn off the VPN. It would seem that OPNsense is trying to pass all traffic through the VPN, but I can't seem to figure out how to fix this. I also can't seem to figure out if I should place the rules in Floating, WAN or LAN.
Title: Re: Use a second gateway for P2P traffic.
Post by: mimugmail on September 13, 2019, 06:01:44 am
Which guide did you follow for setup?
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 13, 2019, 10:24:05 am
I've followed various guides. But there are a number of things I don't understand. Like do I put all of the rules in the same part of the firewall? Should I use source or destination? Do I use floating or LAN or WAN? There seem to be too many variables.

If you meant with the VPN, I acted according to the following directions modifying the details for the provider: http://chronicgeekage.blogspot.com/2019/02/opnsense-and-pia-private-internet-access.html
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 14, 2019, 01:54:29 am
I try to create rules, but it seems that the rules aren't being used. When I place a rule in Floating if I set the rule to be both in and out, on any interface, on any network, with the source and destination ports set to my port range... It seems to do nothing.
Title: Re: Use a second gateway for P2P traffic.
Post by: mimugmail on September 14, 2019, 06:49:46 am
Always use interface where traffic arrives first inbound. Check multi wan howto on OPNsense docs to learn how it works
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 14, 2019, 08:50:42 pm
So... WAN [IN]? I will give that a try.
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 14, 2019, 09:08:53 pm
Okay, so I gave that a try... It is still allowing the traffic to come through.
Title: Re: Use a second gateway for P2P traffic.
Post by: mimugmail on September 15, 2019, 06:47:20 am
Can you check the live log? Then you will see what exactly is blocked.
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 16, 2019, 06:55:23 am
I'm relatively new to OPNsense. Could you please tell me how to do that?
Title: Re: Use a second gateway for P2P traffic.
Post by: mimugmail on September 16, 2019, 07:44:16 am
Menu : Firewall : Log : Live Log/View

There you see which packets are blocked or allowed.
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 19, 2019, 01:55:33 am
I don't know what I'm looking for. Can someone please help?
Title: Re: Use a second gateway for P2P traffic.
Post by: roadrage999 on September 19, 2019, 04:03:28 am
Geek,

Read the following forum post front to back:

https://forum.opnsense.org/index.php?PHPSESSID=0fqidujgkp5roffgihk8svs0l5&topic=4979.msg19771#msg19771

This will walk you through every aspect of the setup and even has spots where others got stuck and solutions to push through.  Read the firewall rules at least 3x before going and attempting to set those up.

Check, Double Check , then Triple check the post and your setup to make sure everything is in line as the initial setup may get you most of the way there and then another user post will get you home. 

If your VPN client is online then its just a matter of ensuring your rules are correct and assigned to the proper interfaces.
Title: Re: Use a second gateway for P2P traffic.
Post by: TheCodeGeek on September 20, 2019, 07:46:52 am
Thank you!