You should consider testing with a single device. Meaning, do not use the script at all. Ensure you are connected to a Swedish VPN Server, then in VPN Director, set that one device (or all your devices doesn't matter) to route over VPN then try launching to see if works first.
Then when you...
Thats a function of DNSmasq in you jffs/config directory, there should be a file call dnsmasq.conf.add
Add either top level domains or a specifc domain, both examples below:
address=/microsoft.com/0.0.0.0...
And.... This is my client.ovpn file. Obviously something thing such as domain and keys are not displayed. Maybe move away from the iOS bubble to have more control over your devices and get a fraction control back? Sorry, never been an Apple fan due to control issues.
# Config generated by...
Those older devices are considered Layer 2 hence the need for TAP server... the new HDHomerun devices to transcoding occurs on the HDHomerun devices so TCP seems to work fine. Either way I prefer my TAP method cuz my old stuff ain't broke.
My config that has worked for many years...
Sorry about the iOS TAP driver thing... that is beyond my control. 100% different standard OpenVPN reduces the port scan issues.
TAP Open VPN Server allows this and works very well. I also have older HDHR-US 3 tuners. Infact this is the only reason I have SERVER1 as a TAP server. Kodi with NextPVR PVR Plugin works well and my remote tv's in a different state jack right in. Full channel guide and everything. I have...
Agreed, this scrip won't as it's purely Domain Name Based, but the baked in feature will since I had to use it a lot before you released this script. I had to IPvFoo a bunch of Domain names and route specific ip addresses over MAN (Man v WAN) didn't make a difference, both the same with Metric...
I haven't tested this yet, but after bulk delete in the file, I'm not sure what happens if completely delete the corresponding policy_yourpocliyname_domaintoip file. I think the script recreates it basically "cleaning up" the ip addresses albiet in a round about way.
WinSCP into router, navigate to /jffs/configs/domain_vpn_routing folder, edit your policy_YOURPOLICYNAME_domainlist and mass delete in the file editor.
Ok, I did some testing and there is indeed some leakage. When I queried my inside policy first, everything worked as expect, however, immediately after I queried my ASN which goes over WAN, URLs tracepathed over WAN which are explicitly added to the Inside Policy. Any appetite for you to give...
@Ranger802004 Which policy takes priority over which policy? I just wanted to validate this with you. I added an ASN to the WAN policy (it's a massive amount of IP's), however, a subset of those domains I wanted to route over VPN, so added those to my "Inside" Policy. I did a tracepath (yes...