OPNsense Forum

English Forums => General Discussion => Topic started by: Sunnyb0y on October 08, 2020, 04:52:45 pm

Title: GateWayGroup Tier "never" is not enforced
Post by: Sunnyb0y on October 08, 2020, 04:52:45 pm
Hello,
แจกสูตรฟรีไฮโลมือถือออนไลน์ (http://madeseo1.mystrikingly.com/)
I have several VPNs connected, each have an interface, and associated gateway.
I created a gateway group that would include only my VPNs gateway in the proper order.

I have then created a rule so that adresseip.com website get routed  out of the FW through this gateway group that only contains VPNs.

The rule is working, since when I disable my openVPN connections one by one, on another PC that gets this rule applied to him, I see that each time my IP as seen by adresseip.com website does indeed change, from one VPN to the next.

So far so good.
But when I turn all VPNs off, I see the gwgroup having all members down, in the firewall logs the trafic still matches the rule I added for adresseip, but instead of failing to connect, opnsense uses the default gateway (without VPN for me) and I see my real IP instead of seeing a blocked page...

Is that normal ? do I need to add a rule to prevent going out a specific gateway ?
if yes, how to do it ? The host should be allowed to use the normal default gateway when all VPNS are down, except for this site adresseip.com...


Thank in davance for your kind help,