I'm running Merlin 386.3_2 on an RT-AC68U. I'm using the OpenVPN client with it set to connect when booted. The kill switch is enabled, and all internet traffic is set to be redirected over the VPN.
I've noticed that traffic is allowed to go over the WAN immediately after rebooting for a short time (about 15 seconds) after the router starts routing and before the VPN finishes connecting. Once the VPN connects, all traffic goes over the VPN. I verified the kill switch works properly if I kill the VPN client over SSH.
It also happens while the VPN is reconnecting after the WAN cable is disconnected and reconnected.
Interestingly, I'm not able to reproduce the problem if I switch from redirecting all traffic to PBR with a rule to send traffic from the entire subnet over the VPN. I would just leave it configured with the PBR rule, but I want to use Diversion and the VPN's DNS server.
I guess I could just configure the firewall to block traffic from going over the WAN, but I'd like to figure out what the problem is. Any ideas?
I've noticed that traffic is allowed to go over the WAN immediately after rebooting for a short time (about 15 seconds) after the router starts routing and before the VPN finishes connecting. Once the VPN connects, all traffic goes over the VPN. I verified the kill switch works properly if I kill the VPN client over SSH.
It also happens while the VPN is reconnecting after the WAN cable is disconnected and reconnected.
Interestingly, I'm not able to reproduce the problem if I switch from redirecting all traffic to PBR with a rule to send traffic from the entire subnet over the VPN. I would just leave it configured with the PBR rule, but I want to use Diversion and the VPN's DNS server.
I guess I could just configure the firewall to block traffic from going over the WAN, but I'd like to figure out what the problem is. Any ideas?