VPN Client on Wifi only

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Sun Sep 24, 2017 14:59    Post subject: VPN Client on Wifi only Reply with quote
Hi

I am a newbie to dd-wrt and have zero linux experience.
I have just bought and configured a Linksys WRT1900ACS with dd-wrt and the vpn client.
It all works perfectly and am very impressed.

What I would love to do is configure it so just the wifi uses the vpn client and anything plugged in via ethernet does not. Alternatively specific ip addresses do not use the vpn client.

Is anything like this possible?

Many thanks Smile
Sponsor
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Sep 24, 2017 17:19    Post subject: Reply with quote
Check out Policy Based Routing. You can specify what devices on your network use the VPN Tunnel via IP Address.
*Whatever IP you put in the box will use VPN while all others do not

Located in Services Tab - VPN Sub Tab.

https://www.dd-wrt.com/wiki/index.php/Policy_Based_Routing

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Sun Sep 24, 2017 17:35    Post subject: Reply with quote
spuriousoffspring wrote:
Check out Policy Based Routing. You can specify what devices on your network use the VPN Tunnel via IP Address.
*Whatever IP you put in the box will use VPN while all others do not

Located in Services Tab - VPN Sub Tab.

https://www.dd-wrt.com/wiki/index.php/Policy_Based_Routing


Thanks that should do it for me Smile
so I just add a list of IP addresses. I have 5 I need to add. Is it just one IP address per line? e.g.

192.168.1.111
192.168.1.113
192.168.1.115
192.168.1.122
192.168.1.125

Sorry if I have this wrong.
I really am a complete noob Wink
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Sep 24, 2017 17:59    Post subject: Reply with quote
No need to apologize! I’m still a novice at most of this. No one starts as an expert.

I haven’t used PBR in awhile, but I believe you also need to include the subnet (the number in an IP address after the /).

Try it first without and then if it doesn’t work put the subnet on the ip addresses in the PBR box.

Here’s a website to help explain as well as an IP Calculator:

https://serverfault.com/questions/49765/how-does-ipv4-subnetting-work

http://jodies.de/ipcalc Mr. Green

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Sep 24, 2017 18:03    Post subject: Reply with quote
I know that it’s one IP Address per line.

I think the subnet is needed if you want to include a range of IP Addresses.

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Sun Sep 24, 2017 19:26    Post subject: Reply with quote
spuriousoffspring wrote:
I know that it’s one IP Address per line.

I think the subnet is needed if you want to include a range of IP Addresses.


Thanks again.
I tried the ip address of the pc I am using as:

192.168.1.103

and then as:

192.168.1.103/32

but I could not browse the web afterwards.
Could ping sites but not browse them as it would time out.
This seems to affect all other devices on the network too.
Browsing is just stopped, dead.
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Sep 24, 2017 20:02    Post subject: Reply with quote
Did you reboot router after setting up PBR?

Do you have a kill switch configured on your VPN?

Those are the two I would try first.

Also, what VPN Provider do you have?

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Sun Sep 24, 2017 20:21    Post subject: Reply with quote
Yes I have rebooted the router.
Result is the same Sad
Not sure about a kill switch but i do not think i have one. Did not know it was possible in dd-wrt.
I am using IPVanish.

Without PBR all clients use the vpn and work very well. Am achieving good vpn speeds of 50 Mbps on a 100 Mbps line.
As soon as I enter an ip in PBR that machine cannot browse the web but all other devices can and are going directly through the isp, not via the vpn (so that much is working).
Hope that makes sense.
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Sun Sep 24, 2017 21:14    Post subject: Reply with quote
all working now Smile

The problem was having Shortcut Forwarding Engine enabled.

http://www.dd-wrt.com/phpBB2/viewtopic.php?p=1092791&sid=4f746f007d7bda32309f8242013e004e
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Sep 24, 2017 21:18    Post subject: Reply with quote
Nice catch! I didn't know that SFE interferes with PBR. Now I do!

Hopefully this'll help someone else.

Glad you got it working Mr. Green

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
Whatsmyip
DD-WRT Novice


Joined: 08 Oct 2017
Posts: 1

PostPosted: Sun Oct 08, 2017 23:24    Post subject: This worked... but now how to restore a kill switch? Reply with quote
After hours of searching this post did the trick. Thank you so much to everyone who contributed. I tried everything and as soon as I deleted the firewall commands in command shell- I was able to tunnel via VPN only through the IP I set in PBR.

Now I want to know how I can reinstate a auto kill switch on the devices using a VPN?

I'm using Nord VPN and inputed the setup manually via their tutorial.

Thank you so much
spuriousoffspring
DD-WRT Guru


Joined: 05 Apr 2017
Posts: 981
Location: Louisiana, USA

PostPosted: Sun Oct 08, 2017 23:29    Post subject: Re: This worked... but now how to restore a kill switch? Reply with quote
Whatsmyip wrote:
After hours of searching this post did the trick. Thank you so much to everyone who contributed. I tried everything and as soon as I deleted the firewall commands in command shell- I was able to tunnel via VPN only through the IP I set in PBR.

Now I want to know how I can reinstate a auto kill switch on the devices using a VPN?

I'm using Nord VPN and inputed the setup manually via their tutorial.

Thank you so much


Check out this topic. Should be what you’re looking for

http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311386

_________________
DD-WRT Installation & Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311117

WRT32X DD-WRT Installation Procedure
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=315569

IPVanish OpenVPN Client Setup TUTORIAL
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=308565

FIRMWARE: OpenWrt SNAPSHOT r8217-2cc821e / LuCI Master (git-18.276.41146-280dd33)
MODEM: ARRIS SURFBoard SB8200
ROUTER: Linksys WRT32X
USB NAS: Western Digital BLACK 1 TB Hardrive + Startech USB 3.0 External SATA III Enclosure
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum