OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • HOWTO - Routing Traffic over Private VPN
« previous next »
  • Print
Pages: 1 ... 7 8 [9]

Author Topic: HOWTO - Routing Traffic over Private VPN  (Read 222383 times)

ligand

  • Newbie
  • *
  • Posts: 11
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #120 on: July 04, 2022, 04:58:03 pm »
Hi Everyone,
Wanted to share a configuration option to help with port forwarding.  My setup:

Interfaces
WAN
VyprVPN
LAN

Thanks to this thread I was able to get Transmission to route out of the VPN interface instead of the WAN interface.  However, Transmission reported that my peer listening port was closed.  I setup port forwarding on the VyprVPN interface to forward inbound traffic to my Transmission host but it didn't work.  After doing a bunch of  tcpdumps, I found that inbound traffic entered the VyprVPN interface but left using the WAN interface. 

I also have an OpenVPN server setup and found a rule in the OpenVPN server rule in that ruleset was affecting my Transmission traffic.   The rule is the one that allows for all traffic to enter OpenVPN (see attachment).  If I disabled the rule then all traffic to and from Transmission went over the VPN.  If the rule was enabled, then I experienced asymmetric routing.  I found that if I unchecked "apply rule immediately" then my routing worked as expected.  :-). Hope this helps.


Logged

immto

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #121 on: October 20, 2022, 04:47:10 pm »
Hello everyone and thanks to you all and especially M4DM4NZ for getting this thread going years ago.  That said I do have a couple issues I'm still ironing out and I'm trying to really understand this.  The original How To said to create a rule for port 500.  Was that a thing back in 2018 because I can't see any reason why I would need this rule.  Any thought on that? 

Also Thank you

Quote from: crissi on January 13, 2022, 06:31:14 pm
Hello,

i hope someone can explain me the implications / correct settings of the openvpn client configuration Don't pull routes and Dont add/remove routes

Every VPN Provider seems to have different settings here.

NordVPN
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Checked

AirVPN
Don't pull routes               -> Checked
Dont add/remove routes    -> Unchecked

PIA
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Unchecked

Can someone please help here?
Thx!


That is what really helped me get this going.  Nowhere is it mentioned that these settings are so important, but they are.  The VPN providers don't even seem to mention them.   
Logged

chenks

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #122 on: December 20, 2022, 10:11:30 pm »
hi, sorry to bump this thread, but i'm a new opnsense user and just looking to check if the instructions at the start of this thread (from 2017) will allow me to do what i'm trying to achieve.

i'm new to opnsense, but not new to basic network config and tinkering with config.

i've added my nordvpn account to opnsense as a vpn client (using https://support.nordvpn.com/Connectivity/Router/1292598142/OPNsense-19-1-setup-with-NordVPN.htm although stopped at the unbound part), and it's showing as connected (albeit no traffic actually routing thru it just now).

i want to route either specific URLs or specific LAN clients thru the VPN (ie not ALL traffic), i believe this will probably be policy based routing?

example
i want to route all traffic from 192.168.50.10 thru the VPN
i want to route any device accessing www.blah.com thru the VPN

i also don't want any DNS leak
Logged

andyblac

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #123 on: September 14, 2023, 02:37:35 pm »
I am having this issue, is theres a known fix yet ?

thanks
andrew
Logged

perrfect

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #124 on: November 07, 2023, 01:51:02 pm »
Quote from: M4DM4NZ on April 10, 2017, 01:34:53 pm
Hi Guys,

Below is a step by step guide to configuring Opnsense 17.1.4 to route LAN traffic out via your private VPN provider.
(In my case, AirVPN)

I have a setup where I want all computers on my LAN to have a direct connection to the Internet, but "Some" computers I want connected to the VPN *cough torrenting cough *


Hello. Thank you for your article. It really works.
How about Multi WAN?
When we have two OpenVPN clients and two LANs.
LAN1 - VPN1
LAN2 - VPN2
If VPN1 is off, all traffic from LAN1 should go via VPN2.
« Last Edit: November 07, 2023, 01:54:10 pm by perrfect »
Logged

beneix

  • Newbie
  • *
  • Posts: 49
  • Karma: 3
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #125 on: December 13, 2023, 02:39:03 pm »
Quote from: crissi on January 13, 2022, 06:31:14 pm
Hello,

i hope someone can explain me the implications / correct settings of the openvpn client configuration Don't pull routes and Dont add/remove routes

Every VPN Provider seems to have different settings here.

NordVPN
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Checked

AirVPN
Don't pull routes               -> Checked
Dont add/remove routes    -> Unchecked

PIA
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Unchecked

Can someone please help here?
Thx!

I am also confused about this - trying to set up a VPN client for PIA, but since I only want certain clients to go via this interface, I was thinking that also for PIA I should check "Dont add/remove routes". Am I wrong?
Logged
OPNsense 24.7.7-amd64 on APU2E4 using ZFS

beneix

  • Newbie
  • *
  • Posts: 49
  • Karma: 3
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #126 on: December 13, 2023, 03:17:50 pm »
Quote from: M4DM4NZ on April 10, 2017, 01:34:53 pm

Step 7.

 - Navigate to Firewall > Aliases > View
 - Add a new Alias
 - Name: VPNTraffic
 - Description : VPNTraffic
 - Type: Host:
 - First entry: 192.168.X.X

NOTE: (enter the IP address of Computers/devices you want to be on the VPN here. I personally enter the IP address of my Wireless router I have attached to my LAN, The wireless router has DHCP enabled so all wireless devices connected to this access point have their traffic passed via the VPN )

Something seems to have changed since the OP - there is nowhere to put "First entry". I have a field "Content", but there I can only choose between a list of other aliases. There is also a "Categories" field.

Where should I enter the ip address(es)?
Logged
OPNsense 24.7.7-amd64 on APU2E4 using ZFS

Hoererser

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #127 on: January 11, 2024, 11:34:37 am »
Quote from: immto on October 20, 2022, 04:47:10 pm
Hello everyone and thanks to you all and especially M4DM4NZ for getting this thread going years ago.  That said I do have a couple issues I'm still ironing out and I'm trying to really understand this.  The original How To said to create a rule for port 500.  Was that a thing back in 2018 because I can't see any reason why I would need this rule.  Any thought on that? 

Also Thank you

Quote from: crissi on January 13, 2022, 06:31:14 pm
Hello,

i hope someone can explain me the implications / correct settings of the openvpn client configuration Don't pull routes and Dont add/remove routes

Every VPN Provider seems to have different settings here.

NordVPN
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Checked

AirVPN
Don't pull routes               -> Checked
Dont add/remove routes    -> Unchecked

PIA
Don't pull routes               -> Unchecked
Dont add/remove routes    -> Unchecked

Can someone please help here?
Thx!


That is what really helped me get this going.  Nowhere is it mentioned that these settings are so important, but they are.  The VPN providers don't even seem to mention them.
Many things can be a waste of your effort, but a helping hand is not.
Logged

ligand

  • Newbie
  • *
  • Posts: 11
  • Karma: 0
    • View Profile
Re: HOWTO - Routing Traffic over Private VPN
« Reply #128 on: June 28, 2024, 04:34:50 am »
Hi All!
I had to redo my VPN configuration and found that these settings work for VPN configurations other than wireguard. 

https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html

Hope this helps.
Logged

  • Print
Pages: 1 ... 7 8 [9]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • HOWTO - Routing Traffic over Private VPN
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2