.-------+------. | Roadwarrior | (OpenVPN-Client) '-------+------' : 192.168.240.6 : WAN / Internet : : 192.168.240.1 .--------+--------. | OpenVPN-Server | (Läuft auf einer VM in VLAN1) '--------+--------' | 192.168.0.126 | VLAN1 (192.168.0.0/24) | | 192.168.0.254 .-----:-------. | OPN:sense +-------. 10.42.0.254 '-----:-------' |10.31.0.254 | | | | VLAN31 VLAN42 (10.31.0.0/24) (10.42.0.0/24) | |10.31.0.10 | |10.42.0.20 .-----+------. .-----+------. | Server1 | | Server2 | '------------' '------------'
push "route 10.31.0.0 255.255.255.0"push "route 10.42.0.0 255.255.255.0"
Name: OpenVPN1Schnittstelle: vlan1Adressfamilie: IPv4IP-Adresse: 192.168.0.126Upstream Gateway: deaktiviertFerner Gateway: deaktiviertPriorität: 255
Netzwerk: 192.168.240.0/24Gateway: OpenVPN1 - 192.168.0.126
VLAN Protokoll Quelle Port Ziel Port Gateway Zeitplan BeschreibungVLAN1: IPv4 * 192.168.240.0/24 * 10.0.0.0/8, 192.168.0.0/16 * * * Allow access from VPN-Clients to local subnets
pass in quick inet from 192.168.240.0/24 to any
If filtering of traffic between statically routed subnets is required, it must be done on the router and not the firewall since the firewall is not in a position on the network where it can effectively control that traffic.