Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.1 Legacy Series
»
[SOLVED] Forcing a single IP out over VPN/blocking if VPN is down
« previous
next »
Print
Pages: [
1
]
Author
Topic: [SOLVED] Forcing a single IP out over VPN/blocking if VPN is down (Read 2105 times)
Callahan
Newbie
Posts: 26
Karma: 0
[SOLVED] Forcing a single IP out over VPN/blocking if VPN is down
«
on:
March 29, 2020, 07:26:53 pm »
Hi,
As the title suggests, I have already configured 99% of this and it works fine. The issue I have is that if the VPN drops (using IPVanish), I want the hosts in the alias list to be prevented from accessing the Internet.
I have read that this can be achieved by tagging the packets and then using that tag to prevent outbound connections to the default WAN gateway. That doesn't work.
A simpler (or so I thought), way of achieving this would be an exact copy of the top rule forcing said clients out of the VPN, but as a deny rule preventing them from getting anywhere. That way, if the only rule allowing them out can't get to it's gateway, the 2nd rule prevents them from getting out.
This should be super simple but in reality, when the VPN gateway is down, the clients are allowed out ovet the default gateway despite having a specific rule that they should match on that would deny them outbound connections.
I'm at a loss as to figure out why.
I've added an attachment that shows exactly what I mean. Can anyone tell me what I'm missing to make this deny rule work?
Thanks!
«
Last Edit: March 30, 2020, 10:19:13 am by Callahan
»
Logged
stefanpf
Jr. Member
Posts: 75
Karma: 5
Re: Forcing a single IP out over VPN/blocking if VPN is down
«
Reply #1 on:
March 29, 2020, 09:00:02 pm »
Maybe this option helps you Out:
Firewall > Settings > Advanced > "Gateway Monitoring" > Skip rules when gateway is down.
Logged
Callahan
Newbie
Posts: 26
Karma: 0
Re: Forcing a single IP out over VPN/blocking if VPN is down
«
Reply #2 on:
March 30, 2020, 10:17:28 am »
Thanks. That seems like a really crazy option to have switched on by default. It literally does the opposite of what anyone would expect. It turns deny rules into allow rules out of the box!
Thanks for your help Stefan!
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
20.1 Legacy Series
»
[SOLVED] Forcing a single IP out over VPN/blocking if VPN is down