Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
OpenVPN interfaces in Gateway Groups
« previous
next »
Print
Pages: [
1
]
Author
Topic: OpenVPN interfaces in Gateway Groups (Read 991 times)
Native2184
Newbie
Posts: 6
Karma: 0
OpenVPN interfaces in Gateway Groups
«
on:
November 15, 2023, 03:49:59 pm »
Hi,
My setup:
- OPNsense 23.7.8_1-amd64
- Two WAN interfaces (KPN & Ziggo) with both IPv4 and IPv6 enabled
- Several VLANs to segregate traffic (Management, IOT, guest, etc)
- VPN connections to several servers in different locations with OpenVPN to OVPN
What I'm trying to achieve is a failover setup with OpenVPN interfaces to be used in firewall rules. So i can route specific traffic over VPN connections. I have setup several OpenVPN connections through different servers, added them to interface and put them in a gateway group.
When I add the gateway group to a firewall rule, it routes the traffic through the primary WAN (KPN), but if I select an individual OpenVPN interface, it works just fine.
Also tried setting up the VPN connections up using UDP (default) and TCP
Other gateway groups with only the KPN and Ziggo interfaces in them behave as expected, but if i throw an OpenVPN interface in the mix, it doesn't seem to work.
All VPN connections are bound to the primary WAN interface, but from what I've read it's better to bind it to localhost so it will reconnect instead of a WAN failure(?)
There's something I'm missing obviously. So I'm hoping to get some pointers in the right direction here.
Logged
Native2184
Newbie
Posts: 6
Karma: 0
Re: OpenVPN interfaces in Gateway Groups
«
Reply #1 on:
November 18, 2023, 12:52:20 pm »
Gentle bump
Is it possilbe to get OpenVPN Client interfaces working in a gateway group or do I have to keep using a specific OpenVPN interface in the rule like it is now
If any more information is needed to clarify, please let me know
Logged
bbh
Newbie
Posts: 5
Karma: 1
Re: OpenVPN interfaces in Gateway Groups
«
Reply #2 on:
November 25, 2023, 02:00:31 pm »
Experiencing the exact same problem using 23.7.8. :'(
Even if I create a group that consists of the WAN interface (set to never) and a single VPN interface (set to tier1) the rules using this group name as the destination gateway to be used gets my traffic out of the door via the WAN interface instead of the VPN interface. Only way I was able to change that behavior is selecting a single (VPN) gateway within the firewall rules. Which defeats the purpose of groups entirely :-(
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
OpenVPN interfaces in Gateway Groups