Todo #8332
closed
pfBlockerNG doesn't include L2TP interface in outbound floating rules
Added by Stuart Wyatt almost 7 years ago.
Updated about 4 years ago.
Description
pfBlockerNG needs an option on the General tab for "L2TP Interface" similar to the "OpenVPN Interface" and "IPSec Interface" options.
Without the option the auto outbound floating rules do not have the L2TP VPN interface selected.
- Target version deleted (
2.4.3)
I am not sure this needs an option? Aren't the interfaces available?
I'm not sure what you mean by "interfaces available". The problem is that there are no options for the L2TP interface similar to the two check box options below:
OpenVPN Interface:
Select to add auto-rules for OpenVPN. This is only required when the OpenVPN Interface is not listed above.
OpenVPN Server (Outbound auto-rules only), OpenVPN Client (Both In/Outbound auto-rules)
These will be added to 'Floating Rules' or OpenVPN rules tab.
IPSec Interface:
Select to add 'Outbound' auto-rules for IPSec. These will be added to 'Floating Rules' or IPSec rules tab.
Mpd5 will create new L2TP interfaces for each client:
l2tp0, l2tp1, l2tp2 etc..
The only way to apply firewall rules on L2TP clients is to use floating rules
see https://redmine.pfsense.org/issues/4727
Something still needs to be fixed.
Either the rule needs to be applied to any/all L2TP interfaces created, or the option to select "L2TP VPN" interface in Rules/Floating/Edit Firewall Rule/Interface shouldn't be there if it won't work.
The former would be the ideal solution, but if it can't be done the UI should not imply that it can be done.
Rules shouldn't be needed for each individual L2TP interface. There is an interface group called "l2tp" which handles rules for all interfaces involved in L2TP internally. See my reply on #4727.
- Status changed from New to Pull Request Review
- Status changed from Pull Request Review to Feedback
- Assignee set to Renato Botelho
- % Done changed from 0 to 100
PR has been merged. Thanks!
Tested on :
2.5.0-DEVELOPMENT (amd64)
built on Tue Oct 06 12:54:27 EDT 2020
FreeBSD 12.2-STABLE
Once I set up L2TP server, the L2TP interface appeared in the list under pfBlockerNG IP and DNSBL tabs. Rules were added on the L2TP interface after I selected it from the list.
The ticket can be resolved.
- Status changed from Feedback to Resolved
Also available in: Atom
PDF