Force a particular device (or an entire VLAN) to use VPN tunnel to the other location?

Comments

5 comments

  • Avatar
    Firewalla

    Can you paste your configuration screen? "allow" is in the rules ... and if you want to route, you should use routes. So I am not sure if you are using the right "button".  Routes for networks can be done here https://help.firewalla.com/hc/en-us/articles/360061592433-Firewalla-Policy-Content-Based-Routing

    "Matching Traffic to Internet ON Network [VLAN] Interface [VPN]..." will route traffic from VLAN network to VPN

    0
    Comment actions Permalink
  • Avatar
    William Smith

    This unfortunately does not work.

     

    0
    Comment actions Permalink
  • Avatar
    William Smith

    Nor does this:

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Your second screenshot should be the right one. Once you apply this route, and if you go look up public IP on the apple TV, it is not showing the VPN IP?

    0
    Comment actions Permalink
  • Avatar
    William Smith

    I set up an iPod Touch as a testbed, disabled MAC randomization, and confirmed the IP address (192.168.0.121).

    When connected to the LAN that has the VPN tunnel, traceroute to a device on the other end of the tunnel shows the connection goes through 10.155.120.1 (the VPN tunnel).

    Traceroute to Google DNS (8.8.8.8) shows the traffic going through my ISP (192.168.3.1)

    I created a new Route:

    Routes

    (+) Add Route

    Matching: Traffic to Internet

    On: iPod-touch (192.168.0.121)

    Interface: (VPN) Tamarac-Purple (OpenVPN)

    Route Preference: Static

    <save>

    traceroute still shows the traffic going through 192.168.3.1 (my ISP).

     

    I installed OpenVPN on the iPod-touch, turned on the Tamarac-Purple VPN, and now traceroute shows my traffic (as expected) going through the VPN (10.155.120.1) as expected.

     

    What am I doing wrong?

     

    0
    Comment actions Permalink

Please sign in to leave a comment.