OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • Allow internet access only over one gateway
« previous next »
  • Print
Pages: [1]

Author Topic: Allow internet access only over one gateway  (Read 1245 times)

murmelbahn

  • Newbie
  • *
  • Posts: 42
  • Karma: 1
    • View Profile
Allow internet access only over one gateway
« on: March 07, 2020, 12:35:09 pm »
Hi all,

I'm using a WireGuard VPN to Mullvad. If configured an interface and a gateway for this. I've created a rule for a alias to use the WireGuard gateway. This works fine for me. The next step would ne to deny internet access for the alias if the interface is down. I've created a second rule to deny any traffic. But this sadly doenst work. Attached is a screenshot which shows the rules for my lan. Maybe someone can help me to configure this correct.

Thanks in advance!
Logged

Maurice

  • Sr. Member
  • ****
  • Posts: 497
  • Karma: 52
    • View Profile
Re: Allow internet access only over one gateway
« Reply #1 on: March 08, 2020, 12:42:49 am »
Try the Skip rules setting (Firewall / Settings /Advanced):
Quote
By default, when a rule has a specific gateway set, and this gateway is down, rule is created and traffic is sent to default gateway.This option overrides that behavior and the rule is not created when gateway is down

Cheers

Maurice
Logged

murmelbahn

  • Newbie
  • *
  • Posts: 42
  • Karma: 1
    • View Profile
Re: Allow internet access only over one gateway
« Reply #2 on: March 08, 2020, 01:02:28 pm »
Hey Maurice,

thanks for your suggestion. Sadly the behavior is still the same. When I disable the Gateway the IP is using the "real" WAN connection.

Any other tipps?
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • Allow internet access only over one gateway
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2