OpenVPN

OpenVPN

OpenVPN
OpenVPN
2025-11-16 17:58:08 - last edited 2025-11-19 21:18:55

Hi.

I'm having a problem with my ACL. After enabling the "DenyAll" rule, I can't communicate with devices from external device. The tunnel works fine without this rule. With this rule, it's visible on both the client and server sides, it receives an IP address, but there's no communication (including to the internet). Only default network, VPN uses the same addresses.

What rule should I add?

  0      
  0      
#1
Options
1 Accepted Solution
Re:OpenVPN-Solution
2025-11-19 11:21:18 - last edited 2025-11-19 21:18:55

Never mind. I forgot to set up an IP group for ACL purposes. That's what happens when you do it at 2-3 a.m. after work. Now works fine.

 

Index description direction politics protocols source target
4 AllowLAN WAN IN Allow All Allowed networks* IPGroup_Any
5 DenyAll WAN IN Deny All IPGroup_Any IPGroup_Any

*local subnets

Recommended Solution
  1  
  1  
#4
Options
3 Reply
Re:OpenVPN
2025-11-17 08:11:50

  @wojtos 

 

What are you trying to achieve and what ACLs do you have set up?

  0  
  0  
#2
Options
Re:OpenVPN
2025-11-17 20:34:32

  @GRL I'm trying to add a rule that allows the OpenVPN client to communicate with devices on the local network. I know this lule must be the 4th rule. Current ACLs:

1 Reject all other countries (not tested with other countries IPs)

2 Omada (works)

3 Plex (works)

4 Reject all connections IPv4 (works, problematic with OVPN)

5 The same v6 (works)

 

With rule 4th tunnel 'works', has local IP, but communication doesen't work, on both sides is visible

Modification ovpn file (comp-lzo) won't work

  0  
  0  
#3
Options
Re:OpenVPN-Solution
2025-11-19 11:21:18 - last edited 2025-11-19 21:18:55

Never mind. I forgot to set up an IP group for ACL purposes. That's what happens when you do it at 2-3 a.m. after work. Now works fine.

 

Index description direction politics protocols source target
4 AllowLAN WAN IN Allow All Allowed networks* IPGroup_Any
5 DenyAll WAN IN Deny All IPGroup_Any IPGroup_Any

*local subnets

Recommended Solution
  1  
  1  
#4
Options