You chose route selected destinations via the VPN and now you are complaining that it actually is routed via the VPN
I think you did not read my comment.
I said that all traffic is routed through VPN, not only IPs that are listed in PBR (if using Route selected destinations via VPN).
"Route selected destinations via WAN" works as expected - the listed IP addresses do not go through the VPN.
In PBR I put only IP addresses 188.144.96.3, 8.8.0.0/16 and "Route selected destinations via VPN" option is used.
If I traceroute any other IP from my PC (in my case google.com, but it could be any address that is different from PBR), it also goes through VPN. But it should not. This option is not working or am I missing something?
I just want for some destination IPs that go through the VPN, but not all the traffic.
Last edited by uvz123a on Sun Dec 31, 2023 1:16; edited 1 time in total
To then add "Route selected Destinations via VPN" is merely redundant.
You are probably right. It is hard to understand all those settings and interdependence between them.
I think I solved my problem. Per Yngve Berg pointed to it, thanks.
Changes from my previous config in the upper screenshot:
⦁ Destination Routing is set to default route
⦁ At Allowed IPs I have listed destination IPs that I want to go through VPN tunnel
If the destination IP is listed, then traffic goes through VPN, otherwise it goes directly through WAN. After a few minutes of testing it looks like that it is working like I want.
I am using a service that is country specific (eg. Netflix). I don't need that all traffic goes through tunnel, only traffic for that service.
Joined: 18 Mar 2014 Posts: 12923 Location: Netherlands
Posted: Sun Dec 31, 2023 7:43 Post subject:
You could have simply set the Source Routing to `Route Selected Sources via the VPN`, from the guide:
Quote:
Route Selected sources via VPN:
This is the classic PBR where everything entered in the PBR box will be route via the VPN, everything else is routed via the WAN.
The default setting is route everything (all sources) via the VPN.