OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • openvpn - client specific override and firewall
« previous next »
  • Print
Pages: [1]

Author Topic: openvpn - client specific override and firewall  (Read 5021 times)

superfox

  • Newbie
  • *
  • Posts: 23
  • Karma: 0
    • View Profile
openvpn - client specific override and firewall
« on: January 09, 2019, 08:41:53 am »
Hi there!

I have an openvpn server with the settings see attached.

For this I have set up a client specific override. After connecting, the client is assigned an IP from the correct network based on the common name.

However, the client can not send data through the tunnel, but it works great for non-csc clients.

Did i forgot something?
Logged

superfox

  • Newbie
  • *
  • Posts: 23
  • Karma: 0
    • View Profile
Re: openvpn - client specific override and firewall
« Reply #1 on: January 09, 2019, 08:42:58 am »
and here the firewall rules attached
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: openvpn - client specific override and firewall
« Reply #2 on: January 12, 2019, 05:30:02 pm »
I don't think that the Tunnel Network can be outside of servers Tunnel Network. Please set one static IP from the Tunnel Network of server and test again.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

superfox

  • Newbie
  • *
  • Posts: 23
  • Karma: 0
    • View Profile
Re: openvpn - client specific override and firewall
« Reply #3 on: January 15, 2019, 11:08:07 am »

I changed the tunnel subnet in csc-config to 10.4.2.100/30

So now the server get´s the first ip .101 and the client the second ip .102

Hope this step was correct?


Thanks, it´s working now.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: openvpn - client specific override and firewall
« Reply #4 on: January 15, 2019, 04:54:42 pm »
This should do it, yes :)
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • openvpn - client specific override and firewall
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2