I haven't done testing as detailed as yours but entering the same 6 domains using the dnsmasq method, my IPSET site has currently 1225 entries (vs the 146 I get from asnum 2906). I don't get the netflix unblocker/proxy error any longer... I only access via Fire TV or dedicated app on the TV...
Hi Xentrk,
thanks for the explanation.
Interestingly for Netflix the ASN wasn't working at all for me, I was only able to see a single movie :-D the 2906 created 146 entries in the IPSET while the dnsmasq has created 800+ as of now.
Just run the update in amtm and got the new autoscan.sh...
Hi Xentrk,
first let me thank you as usual for your replies.
I have condensed all my answers in a single post.
Policy Rules (strict) has always been active for me. My first question is how do you analyse dnsmasq.log? I know how to follow it from Diversion (or use the tail command you gave)...
Mmm not sure what I said above is correct. I have added the ASNUM and I got 148 entries. But when I use the autoscan or the dnsmasq file the number of entries doesn't increase.
I have tried running nat-start and I see it executes a lot of commands, including those I'd expect to be deleted (i.e...
Mmm I think it is just a matter of waiting as I now see 6 entries... Do they get added retrospectively?
If so, do I have a way to use both the dnsmasq filter and the ASNUM? Or the latter I execute deletes the entries created by the former?
In other words, can I do
x3mRouting 4 0 NETFLIX...
Hi Xentrk,
EDIT: RESOLVED - See post #135 where I have left the last 2 questions. I am not deleting these posts as they may help somebody having similar issues - MODS please let me know if you prefer I delete them.
following your suggestion, I have now switched my VPN clients so I no longer...
Ah right! I see this, which looks correct as 0x3000 is VPN5 while 0x8000 is WAN.
xxx@RT-AX88U-8880:/tmp/home/root# iptables -nvL PREROUTING -t mangle --
line
Chain PREROUTING (policy ACCEPT 80210 packets, 32M bytes)
num pkts bytes target prot opt in out source...
Thanks for fixing it! OK didn't realise I need to recreate the rule in those cases. Will have a look at the script you mentioned, I am a complete newbie so will probably need to come back for further help :-)
Hi Xentrk,
now that the above is solved I am looking at a way to make it better :-)
Rather than having a generic rule for the whole traffic of the device to go via VPN5, I just want a specific subset of traffic to go to the VPN5.
I don't think I can create a simple rule in the UI of VPN...
Hi Xentrk,
thanks for your reply!
I agree swapping VPN1 with VPN5 would make it easier as I could manage everything from the UI. At the moment I was only running some tests as I wasn't sure I actually needed this dedicated routing.
For whatever reason the code you suggested was giving me an...
Hi Xentrk,
I am trying to add a rule to have a specific ip routed via a different VPN client. When I set it up in the Merlin UI, the rule gets added with a priority too low (10901 in the example below).
xxx@RT-AX88U-8880:/tmp/home/root# ip rule show
0: from all lookup local
9990: from...
So far so good... Been using it all day, in and out of work VPN, many devices etc. and all seems to be working properly (TV, mobile, laptops etc.). Will let you know should I find any surprises but for now it's perfect...
Thanks for this great tool!
Hi, cross-posting from another thread as it is relevant to Diversion and can help other users.
In the page https://diversion.ch/faq-reader/diversion-is-installed-and-i-still-see-ads.html it is mentioned
Newer Android Devices use hard coded IP addresses for some domains. This circumvents...
I have finally found the issue and it is described in the thread
https://forums.oneplus.com/threads/secondary-dns-forced-to-8-8-8-8.999920/
Do you see any issue if I hard code my router IP as primary and secondary DNS in LAN --> DHCP Server --> DNS and WINS Server Setting?
Hi, apologies for resurrecting this old thread but I have learnt a lot from it! Can I ask you what is the problem with having the traffic using NordVPN DNS? I have NordVPN too and have gone through all the hoops to make it work with Diversion etc. Why do you prefer to only have the Cloudflare...