What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

378.53 - Directing all subnet traffic to OpenVPN

jazzy_jeff_81

Occasional Visitor
I just installed the new firmware and love the new features. Thanks.

I have a question about setting up the OpenVPN rule to force traffic on a specific subnet to use the VPN for internet traffic.
I tried some time ago to get the Guest network setup on my Asus AC87R to receive a different ip subnet and then connect to the OpenVPN connection. I could never get this to work, so I purchased a cheap Linksys E1200 router, loaded DDWRT and setup the OpenVPN connection on there.
I still had my main connection go through my Asus router, but I had another wireless SSID that has it's own DHCP subnet (192.168.2.0) and has a connection for OpenVPN to get internet. To visualise the setup, I have an ethernet cable going from the Linksys WAN port into the LAN port of the Asus. I followed some instructions on setting up the firewall commands and it works great. Well not great, which is why I am here. The connection on the linksys is a little slow and I have read that it is due to the poor cpu on the router. So I'd like the vpn back on the asus, and figure that as I still can't get a different dhcp scope working on the guest network on the asus, I could still use the linksys to broadcast the other ssid and assign ip's on the 192.168.2.0 subnet.

The new firmware with the policy rule sounded great as I could direct traffic with rules, but I can't get this to work either :-) . So I have my assign assigning the Linksys an IP of 192.168.1.2 (the linksys ip is actually 192.168.2.1). In the rule section of the openvpn tab I have the source IP of 192.168.1.2 and I was thinking the destination would be 192.168.2.0, but this isn't working and I am thinking I am completely misunderstanding this.. I've tried all of these destination IP's too.
- 192.168.1.0
- 192.168.1.1
- 192.168.1.2
- 192.168.2.0
- 192.168.2.1

I've also tried reversing these ips and put them in the source ip, and tried different combinations with the destination ip, but I still can't get it too work.

Just to recap. i would like all client connected on my linksys with the 192.168.2.x address to use the openvpn client connection on the asus. The asus clients on 192.168.1.x still need to use the regular isp connection.
By the way, if I see the rule to all traffic for the vpn, then the clients on the linksys do route through the vpn connection, so I know the linksys and asus are talking properly, it's just the rule to get the linksys clients using the vpn only isn't working.

Thanks for any help.
 
If the clients are behind the Linksys, then the rule source must be the WAN IP of the Linksys, which would be 192.168.1.2.
 
Thanks RMerlin. What would the destination address be then, keeping in mind I want all IP addresses in the 192.168.2.0 scope to use the VPN? Would it just be 192.168.2.0, or can I only specify specific addresses individually? i.e. Source - 192.168.1.2 Destination - 192.168.2.2, Source - 192.168.1.2 Destination - 192.168.2.3, Source - 192.168.1.2 Destination - 192.168.2.4, Source - 192.168.1.2 Destination - 192.168.2.5 etc.
 
Thanks RMerlin. What would the destination address be then, keeping in mind I want all IP addresses in the 192.168.2.0 scope to use the VPN? Would it just be 192.168.2.0, or can I only specify specific addresses individually? i.e. Source - 192.168.1.2 Destination - 192.168.2.2, Source - 192.168.1.2 Destination - 192.168.2.3, Source - 192.168.1.2 Destination - 192.168.2.4, Source - 192.168.1.2 Destination - 192.168.2.5 etc.

Leave the destination empty. It will automatically fill with 0.0.0.0, which means "all destinations".
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top