defguard icon indicating copy to clipboard operation
defguard copied to clipboard

Updating "allowed ips" in location settings does work

Open syphernl opened this issue 1 year ago • 4 comments

Describe the bug By-default the allowed ips list of a location is 0.0.0.0/0 so it will route all traffic. When I emptied out the field and used "Predefined traffic" in the client my traffic would still be routed through the VPN instance. Adding in a subnet (e.g. 10.100.0.0/24) didn't prevent it from routing all traffic over the VPN either

To Reproduce Steps to reproduce the behavior:

  1. Go to location settings
  2. Empty out the Allowed IP's field (or fill in something else than the default 0.0.0.0/0)
  3. Save
  4. Connect with the Defguard client set to "Predefined traffic"
  5. See that the external IP is still that of the VPN instance.

Expected behavior Traffic that doesn't match the allowed ips should not be routed over the Defguard tunnel.

Version information

  • Defguard Core version: v0.9.1
  • Defguard Gateway version: v0.9.1. (?)
    • Operating system and version running the gateway: Ubuntu 22.04

syphernl avatar Mar 14 '24 08:03 syphernl

Is it a MFA enabled VPN?

teon avatar Mar 14 '24 11:03 teon

i am having the same problem but cant get to my network from the remote end ( cant get to remote lan when lan ip range is set in allowedip

jonboy86 avatar Mar 15 '24 05:03 jonboy86

Same here, and without MFA.

Defguard Core version: v0.10.0 Defguard Gateway version: v0.6.2 Operating system and version running the gateway: Debian 12

openl4m4 avatar Apr 02 '24 12:04 openl4m4

Deleting location on client and re-install is helped for me.

LulzLoL231 avatar Apr 09 '24 23:04 LulzLoL231

@syphernl @openl4m4 did you update your client config after changing the location settings in the dashboard? It needs to be done manually: https://defguard.gitbook.io/defguard/help/configuring-vpn/add-new-instance/update-instance

t-aleksander avatar Jun 03 '24 07:06 t-aleksander

Closing - since most likely the client wasn't updated. If it's an actual bug we can reopen.

teon avatar Jul 08 '24 11:07 teon