# OpenVPN: external firewall zone? What should go there?

**URL:** https://discuss.freedombox.org/t/openvpn-external-firewall-zone-what-should-go-there/476
**Category:** Uncategorized
**Created:** [November 11, 2019, 1:25am UTC](https://discuss.freedombox.org/t/openvpn-external-firewall-zone-what-should-go-there/476 "2019-11-11T01:25:47Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![Sunil](https://discuss.freedombox.org/user_avatar/discuss.freedombox.org/sunil/32/8_2.png) [@Sunil](https://discuss.freedombox.org/u/Sunil)
#### Post date: [August 4, 2020, 5:08pm UTC](https://discuss.freedombox.org/t/openvpn-external-firewall-zone-what-should-go-there/476/3 "2020-08-04T17:08:22Z")

</div>

There might be a different way to solve the problem. That is to enable the “masquerade” flag on the “internal” firewall zone by running something like this:

```auto
firewall-cmd --zone=internal --add-masquerade
firewall-cmd --zone=internal --add-masquerade --permanent

```

However, I have not evaluated the (security) consequences of doing this. In your particular case, this may not be bad as you have a single network interface. I have also not tested it.

---

_[View the full topic](https://discuss.freedombox.org/t/openvpn-external-firewall-zone-what-should-go-there/476)._
