Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
Different gateway for LAN clients
« previous
next »
Print
Pages: [
1
]
Author
Topic: Different gateway for LAN clients (Read 650 times)
gigo90
Newbie
Posts: 8
Karma: 0
Different gateway for LAN clients
«
on:
August 11, 2024, 02:52:31 pm »
Hello,
i'm struggling to find information about this topic.
I would like two different clients on my LAN to use two different gateways.
My configuration, at the moment use 2 WAN in failover configuration (WAN1 fiber and WAN 2 lte). I also have a VPN Client that connect my OPNsense box to a VPN provider (in order to be geolocalized in a specific country).
I set up a gateway group which contain: WAN1+WAN2+VPN and used this gateway with DHCP server.
With this configuration when the VPN is active all the clients within the LAN will use the VPN as gateway, if the VPN is down, i still have the failover option working.
Now the point is that only specific clients, should not use the VPN as gateway but the failover should continue to work. All the clients must be on the same LAN cause they need to "see" each other.
My idea was to have two different gateway group: GW1=WAN1+WAN2+VPN and GW2=WAN1+WAN2, but i don't know how to assign the GW2 only to clients don't the VPN.
Hope the explenation is cleat
Many thanks
Logged
dseven
Sr. Member
Posts: 301
Karma: 33
Re: Different gateway for LAN clients
«
Reply #1 on:
August 11, 2024, 04:27:15 pm »
You should be able to do that with firewall rules on your LAN. Create rules that match your clients, and select the gateway group for each accordingly, remembering that the first matching rule (from the top down) will be selected.
Logged
dseven
Sr. Member
Posts: 301
Karma: 33
Re: Different gateway for LAN clients
«
Reply #2 on:
August 11, 2024, 04:40:17 pm »
P.S. you might need a rule at the top for DNS with destination "This Firewall" and gateway set to "default", otherwise DNS requests from source matching your new rules could get sent to your VPN gateway and fail.
Logged
gigo90
Newbie
Posts: 8
Karma: 0
Re: Different gateway for LAN clients
«
Reply #3 on:
August 11, 2024, 08:30:46 pm »
Hi, many thanks for your help.
I tired this configuration, but not shure if i understood well.
Protocol Source Port Destination Port Gateway
IPv4 * This Firewall * * * *
IPv4 * 192.168.1.129/24 * * * WAN_GW_GROUP_NOVPN
IPv4 * LAN net * * * WAN_GW_GROUP
Unfortunatelly, seams it's not working as expected. When this first 2 rules are active all the traffic (included the peer .129) uses the "NOVPN". If disabled all traffic is routed through VPN.
Any idea? Thanks
Logged
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: Different gateway for LAN clients
«
Reply #4 on:
August 11, 2024, 08:39:21 pm »
Maybe you want 192.168.1.129/
32
and not the entire /24 subnet?
Logged
dseven
Sr. Member
Posts: 301
Karma: 33
Re: Different gateway for LAN clients
«
Reply #5 on:
August 11, 2024, 09:00:11 pm »
Yeah, that should be /32. I'm a bit surprised that it even allows that error.
Also the DNS rule should have "This Firewall" as the *destination*, not the source, protocol "TCP/UDP" and port 53 ("DNS").
Logged
gigo90
Newbie
Posts: 8
Karma: 0
Re: Different gateway for LAN clients
«
Reply #6 on:
August 12, 2024, 11:00:05 am »
Thanks to both of you!
I'll try and let you know.
EDIT: configuration tested, seems all ok. Thanks again
«
Last Edit: August 12, 2024, 05:07:06 pm by gigo90
»
Logged
gigo90
Newbie
Posts: 8
Karma: 0
Re: Different gateway for LAN clients
«
Reply #7 on:
August 18, 2024, 09:09:02 pm »
May i ask you guys if there is a way to set specific services (from a client) to use a specific WAN?
When the OpenVPN client on OPNsense is enabled, my video on-demand service (amaz....) is not "happy" cause i'm not geo-localizated in the country of subscription.
I can't use the IP based solution (as per my previuos request), cause the TV box should use the VPN to access to content abroad (and use the VPN tunnel as gateway) but only for the video service, should use my in-country WAN.
Thanks
Logged
REB00T
Newbie
Posts: 35
Karma: 1
Re: Different gateway for LAN clients
«
Reply #8 on:
August 18, 2024, 10:53:25 pm »
You can try making a custom dnsmasq config file to put resolution results for certain domains in a specific alias and make rules using that. It is a bit painful to find all the required domains but it can work. Also when it comes to cdn domains (Akamai e.t.c) try to be as specific as possible, and even then it might not work perfectly as these are probably shared between services.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
Different gateway for LAN clients