OPNsense Forum

English Forums => General Discussion => Topic started by: eagle75 on October 11, 2023, 10:09:24 PM

Title: Route 1 IP over WireGuard VPN
Post by: eagle75 on October 11, 2023, 10:09:24 PM
I have OPNSense and I have WireGuard setup for Private Internet Access.  I want to be able to route my downloader machine over that VPN so only that server goes over the tunnel all the rest of the network goes out the default non VPN way.  Any help would be appreciated...I have tried many different tutorials to no avail.
Title: Re: Route 1 IP over WireGuard VPN
Post by: cookiemonster on October 11, 2023, 10:34:47 PM
please consider this one https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html
If you get stuck, inform at which step you get.
Title: Re: Route 1 IP over WireGuard VPN
Post by: eagle75 on October 12, 2023, 02:41:52 PM
Thanks...I am stuck here when they tell you to make the first rule...what interface is it on?  VPN one or LAN?
Title: Re: Route 1 IP over WireGuard VPN
Post by: cookiemonster on October 12, 2023, 02:54:31 PM
From that documentation, LAN.
Title: Re: Route 1 IP over WireGuard VPN
Post by: tiermutter on October 12, 2023, 03:13:08 PM
If you have IPv6 working, remember to do the same for v6 or block it for this device.
Title: Re: Route 1 IP over WireGuard VPN
Post by: eagle75 on October 12, 2023, 11:03:12 PM
I tried all of that and im still not getting the VPN IP for the external IP of the one machine allowed to go over the VPN
Title: Re: Route 1 IP over WireGuard VPN
Post by: eagle75 on October 12, 2023, 11:11:40 PM
Actually it looks reversed...the one machine has my ISP's IP for external and all other machines have the VPN IP...how can I switch that
Title: Re: Route 1 IP over WireGuard VPN
Post by: tiermutter on October 13, 2023, 06:21:31 AM
Screenshot of your rule and alias?
Title: Re: Route 1 IP over WireGuard VPN
Post by: eagle75 on October 13, 2023, 05:22:29 PM
Not reversed sorry I didn't realize I had my Mac client connected...its just not working...the machine that should have the VPN IP still has my ISP IP.
Here are the Rules for Lan and Floating.
Title: Re: Route 1 IP over WireGuard VPN
Post by: tiermutter on October 13, 2023, 08:18:45 PM
You need to invert destination.
However, if the alias does not need to reach other subnets via firewall, you can also set any for destination (without invert).
Title: Re: Route 1 IP over WireGuard VPN
Post by: newsense on October 16, 2023, 02:12:42 AM
There's no justification for the floating rule, and it's wrong anyway.