Yes, done that, opnsense offers some nice config options and it is nice to not be bound to the quirks of one vendor.
VPN Director, AMTM and some other scripts are very practical when in need for a quick country switch but there seems to be no way to reliably configure vpn a killswitch, leaks...
I do believe i might have an old tplink with openWRT for testing reachable, never used VLAN before and i agree that consumer products are time consuming.
Thanks for the recommendations, will look into these products, just need to connect few raspberrys & phones that are scattered around the House.
Dabbling around with a new Opnsense Box.
Added the RT-AC86U (latest fw) as Access Point, everything works.
But i just cannot get it to work in a VLAN, am i right to assume that this Asus Model does not support being AP via VLAN?
In all fairness, you might want to let people also know that there is currently no 100% killswitch possible with some ASUS routers if it is even possible with any and if it is not 100% then it is not a killswitch, you cannot have half a killswitch or one that works in certain conditions.
It seems to work differently then my previous AC86U. Once you give VPNDirector a subnet and VPN you are not able to select IPs from that subnet to go out through a different vpn, which i was able to do on AC86U.
This and the fact that the GT-AX6000 it takes way longer to boot up makes me wonder...
Yes and there might be other times when this happens, might want to check if this also can happen when ISP do they there daily reset.
I was happy snipping the GT-AX6000 for a good price and was looking forward to a new deep dive and setup with rpi pihole but it turned out in allot of frustration...
The leak that happens is for a very short time window, enough to expose LAN clients but not enough for all this IoT and other software you mentioned to stay up.
I am not saying that your coding is at fault but you indicate yourself that the router is not to be trusted and can ignore any rules...
How do you achieve 100% uptime when there is a vpn switch happening due to Load threshold?
I thought vpnmon would start the other vpn slot in such a case, switch over and disable the previous vpn, instead of going through the cycle with downtime and LAN clients disconnected.
Can't figure out what i am doing wrong in my pihole / vpn setup (Accept DNS Configuration: Disabled with VPN Director policy rules) and how to have no DNS leaks on my GT-AX6000.
Tried your variations but the moment i add my ISP to WAN DNS the DNS leaks are flooding in.
I am working on having no DNS leaks and making sure that ALL traffic goes always through the VPN hence why i come to killmon.
vpnmon is watching over 2 vpn clients with same exit point.
VPN Director has 2 rules, ovpn1 and ovpn2 both for 192.168.50.0/24
killmon paranoid mode wouldn't let vpnmon...
Following happened.
Killmon enabled, watching vpnmon-r2 and also watching dns traffic with eibgrad script, also pinging 8.8.8.8 from LAN PC.
Made a change in web UI WAN Internet connection and pressed apply.
Once the UI finished loading 100% and page was reloading i pressed R for reset in...
VPN Director works differently in 388.1 GT-AX6000 then on my RT-AC86U.
Used to have two VPN clients running with different exit points. VPN director was set to route all through VPN1 and then specific hosts were set to use VPN2.
This doesn't seem to work in 388.1 and i would have to manually add...
While experimenting with this script i wonder how to stop or skip parts of the VPN reconnect. Don't get me wrong, i love starring at it doing it's thing!
Setting for reboots and/or resets via vpmon script to go straight and connect to last known good VPN directly and bypass wan checks and...