User Tools

Site Tools


pfsense:vpn:openvpn:assign_a_fixed_ip_to_a_remote_client

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
pfsense:vpn:openvpn:assign_a_fixed_ip_to_a_remote_client [2021/02/17 14:29] – [Configure Firewall Rules for this User] peterpfsense:vpn:openvpn:assign_a_fixed_ip_to_a_remote_client [2021/02/19 09:56] (current) – [Configure Firewall Rules for this User] peter
Line 1: Line 1:
 ====== PFSense - VPN - OpenVPN - Assign a fixed IP to a remote client ====== ====== PFSense - VPN - OpenVPN - Assign a fixed IP to a remote client ======
  
-Assigning a fixed IP to a client that connects to a VPN, in particular OpenVPN, with a specific user, can then be used in firewall rules.+By assigning a fixed IP to a client that connects to a VPN allows this IP to be used in firewall rules. 
 + 
 +<WRAP info> 
 +**NOTE:**  It is assumed that an OpenVPN server has already been created and one or more correctly configured users exist. 
 +</WRAP>
  
-It is assumed that an OpenVPN server has already been created and one or more correctly configured users exist. 
  
 ---- ----
Line 11: Line 14:
 Navigate to **VPN -> OpenVPN**. Navigate to **VPN -> OpenVPN**.
  
-In **Servers**, check the network used by the specific VPN Server.+In **Servers**, check the Tunnel Network used by the specific VPN Server.
  
 In this case it is **10.20.30.0/24**. In this case it is **10.20.30.0/24**.
  
-The fixed IP address for the client must be a unique IP within this subnet, lets say for example **10.20.30.69**.+<WRAP info> 
 +**NOTE:**  The fixed IP address for the client must be a unique IP within this subnet
 + 
 +For example **10.20.30.69**. 
 +</WRAP> 
  
 {{:pfsense:vpn:openvpn:pfsense_-_vpn_-_openvpn_-_servers.png?800|}} {{:pfsense:vpn:openvpn:pfsense_-_vpn_-_openvpn_-_servers.png?800|}}
Line 42: Line 50:
  
   * Server List:  **Select the desired OpenVPN server**.   * Server List:  **Select the desired OpenVPN server**.
-  * Common Name:  **peter**.  This needs to be the **exact** name of the user+  * Common Name:  **peter**.  This needs to be the **exact** name of the useras identified in the earlier step **Identify the user to whom we want to assign the IP just chosen**.
-    * This should be exactly the same as identified in the earlier step **Identify the user to whom we want to assign the IP just chosen**.+
  
 {{:pfsense:vpn:openvpn:pfsense_-_vpn_-_openvpn_-_client_specific_overrides_-_general_information.png?800|}} {{:pfsense:vpn:openvpn:pfsense_-_vpn_-_openvpn_-_client_specific_overrides_-_general_information.png?800|}}
Line 83: Line 90:
 Firewall rules can therefore be configured using this IP. Firewall rules can therefore be configured using this IP.
  
-By placing the IP 10.20.30.69 in the Source field, we can decide which IP our VPN user can access and which ports/services+By placing the IP 10.20.30.69 in the Source field, we can decide which IPs our VPN user can access and which ports/services.
- +
-In fact, they are exactly rules as if the OpenVPN interface were a physical interface and User1 was using a PC with a fixed IP.+
  
 +For example:
  
 +  * Access is granted to IP Address 192.168.1.123 for the user connecting on 10.20.30.69, i.e. peter.
 +  * All other traffic is blocked.
  
 +{{:pfsense:vpn:openvpn:pfsense_-_firewall_-_rules_-_openvpn_-_updated.png?800|}}
  
 <WRAP info> <WRAP info>
-**NOTE:**  The rules above allow only the address 10.20.30.69, to access the IP 192.168.1.x on any port.+**NOTE:**  The last deny rule is not actually needed.
  
-The remaining traffic will be blocked! +It is only put in to to make explicit the deny which in fact is how the firewall behaves if no rule is applied.
- +
-The last deny rule is actually not needed.  It is only put in to to make explicit the deny which in fact is how the firewall behaves if no rule is applied.+
  
 </WRAP> </WRAP>
 +
 +
  
 ---- ----
Line 103: Line 112:
 ===== References ===== ===== References =====
  
-https://www.firewallhardware.it/en/pfsense-and-openvpn-how-to-assign-a-fixed-ip-on-remote-client/+
pfsense/vpn/openvpn/assign_a_fixed_ip_to_a_remote_client.1613572186.txt.gz · Last modified: 2021/02/17 14:29 by peter

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki