Community discussions

MikroTik App
 
onlineuser
Member Candidate
Member Candidate
Topic Author
Posts: 250
Joined: Thu Aug 06, 2015 12:10 pm

firewall rules for bridge for ovpn interfaces

Tue May 22, 2018 10:48 pm

Hello,

I created a bridge called "ovpn" which includes the ovpn interfaces "ovpn-in1" to "ovpn-in4" (my ovpn server on the RB offers up to 4 clients a connections to the RB). Because it is not possible to add dynamic interfaces (which are not running all the time) to firewall rules, I tried to solve it with a bridge.
Moreover, when two connections are running and a thid client tries to connect a new dynamically ovpn interface will be created - so it is not possible to set firewall rules for these interfaces.

When I add the same rule with "ovpn-in1" interface instead of "ovpn" (bridged ovpn ports) the rule works but when I replace the "ovpn-in1" interface with the "ovpn" (interfaces ovpn-in1, ovpn-in2, ovpn-in3, ovpn-in4) the rule does not work and the traffic between the ovpn interfaces and the LAN_Buero bridge will not be forwarded.

Is this a bug in ROS 6.42?

Is there any solution for this problem?

Why for every client will be created a seperated ovpn interface? OpenVPN on Linux systems does not have the same behavior.

Thanks, very much.
You do not have the required permissions to view the files attached to this post.
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 2098
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Krugersdorp (Home town of Brad Binder)
Contact:

Re: firewall rules for bridge for ovpn interfaces

Wed May 23, 2018 12:32 am

Create an interface list and make oven-in1, etc as a member of this, then use in-interface-list=ovpn in firewall rules
 
onlineuser
Member Candidate
Member Candidate
Topic Author
Posts: 250
Joined: Thu Aug 06, 2015 12:10 pm

Re: firewall rules for bridge for ovpn interfaces

Thu May 24, 2018 7:37 pm

Thanks, it works. :-)

Who is online

Users browsing this forum: Laxity, nescafe2002 and 54 guests