Link to home
Start Free TrialLog in
Avatar of tonelm54
tonelm54

asked on

pfSense OpenVPN user group firewall rules

Using pfSence and OpenVPN can you control which users/groups can access which urls? I have 1 web server and using SNI I have multiple sites over HTTPS, but i want to control which they have access to. I didnt really want users to sign in again to the website after signing into the VPN (so kinda single signon, but cant modify the webserver to include any single sign on options).
Avatar of bbao
bbao
Flag of Australia image

i am wondering if pfSense can recognise URL instead of just HTTP/HTTPS traffic at its firewall level (layer-3), see below the official guide for the fields available for a firewall rule. if can recognise OpenVPN users (actually at IP layers - the subnet for OpenVPN, not individual user), not URL.

https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-basics.html
Install SquidGuard package on pfsense and filter urls.
You can authenticate users with radius or active directory which supports groups.

​pfSense user local user database supports groups but its best practice to use an authentication system like radius server or AD for Enterprise infra.

Here is the how to doc
https://docs.netgate.com/pfsense/en/latest/cache-proxy/squidguard-package.html
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.