1
Virtual private networks / OpenVPN ignoring Firewall Rules
« on: June 23, 2024, 05:10:26 pm »
Hello Guys,
i have the following setup in my lab and having some trouble with the corresponding firewall rules:
- OPNsense as OpenVPN Instance (server) [OPNsense 24.1-amd64] -> 192.168.100.1
- Server 1 connected via .ovpn [Debian 12 Bookworm] -> 192.168.100.240
- Server 2 connected via .ovpn [Debian 11 ] -> 192.168.100.241
- Client [MacOS] -> 192.168.100.105
As you might noticed i have some Client specific overrides in place for the ip addresses.
My goal here is that i can communicate freely within the VPN Network.
As soon as the the Server 2 tries to access a service on Server 1 i am prompted with a "Default deny / state violation rule" message in the live view of the Firewall Rules.
I places rules in the VPN Interface itself in the OpenVPN Group and even in the WAN interface and disabled "Block private networks" there for testing.
But none of the rules are working, or being matched.
Even though i have tested, any any rules, as well as rules just for the /24 subnet of the vpn.
But it seems the OPNsense just ignores my rules.
i have the following setup in my lab and having some trouble with the corresponding firewall rules:
- OPNsense as OpenVPN Instance (server) [OPNsense 24.1-amd64] -> 192.168.100.1
- Server 1 connected via .ovpn [Debian 12 Bookworm] -> 192.168.100.240
- Server 2 connected via .ovpn [Debian 11 ] -> 192.168.100.241
- Client [MacOS] -> 192.168.100.105
As you might noticed i have some Client specific overrides in place for the ip addresses.
My goal here is that i can communicate freely within the VPN Network.
As soon as the the Server 2 tries to access a service on Server 1 i am prompted with a "Default deny / state violation rule" message in the live view of the Firewall Rules.
I places rules in the VPN Interface itself in the OpenVPN Group and even in the WAN interface and disabled "Block private networks" there for testing.
But none of the rules are working, or being matched.
Even though i have tested, any any rules, as well as rules just for the /24 subnet of the vpn.
But it seems the OPNsense just ignores my rules.