OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Road Warrior IPsec & Split-Tunnel
« previous next »
  • Print
Pages: [1]

Author Topic: Road Warrior IPsec & Split-Tunnel  (Read 3041 times)

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
Road Warrior IPsec & Split-Tunnel
« on: June 16, 2019, 06:13:24 am »
I followed this guide to get IPsec VPN working with Android using strongswan client and IKEv2.

https://wiki.opnsense.org/manual/how-tos/ipsec-rw-srv-eaptls.html

I connect just fine and can access the the firewall web interface on the LAN address but it is split tunnel.

I would like to force the Android phone to force all traffic over the tunnel. How can I do that?

If I can't force all traffic over the tunnel I would at least like to force dns resolution to take advantage of my pihole on mobile.
« Last Edit: June 17, 2019, 02:30:09 pm by csmall »
Logged

csmall

  • Full Member
  • ***
  • Posts: 121
  • Karma: 5
    • View Profile
Re: Road Warrior IPsec & Split-Tunnel
« Reply #1 on: June 18, 2019, 11:51:54 am »
I tried a couple of things I found after searching the forums.

I tried changing the p2 local network to 0.0.0.0/0 and creating an outbound NAT rule on the WAN interface with a source of the VPN address pool network translated to the WAN address. After these changes when I connected to the tunnel I could no longer get to the internet.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • Road Warrior IPsec & Split-Tunnel
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2