Sorry I am not where I can take another screenshot, however the missing parts are at the top the All Traffic is 192.168.50.0/24 and the part at the bottom is route 192.168.25.100 255.255.255.255 vpn_gateway and that is a local machine on the other side of the VPN, I can get to it no problem with All instead of Policy Rules, but with it set that way if the VPN goes down it uses my regular internet instead of just thinking there is NO internet like it does with Policy Rules (which is what I want). As for it being old firmware it is because it is an old router and that is the newest firmware I can get for it. I only use it for temp stuff most the time it is off.Post your screenshot again without the IP information blanked out. There is no reason to hide private IP addresses, it just makes problems more difficult to diagnose.
Look in the system log for error messages when you start the VPN client.
You appear to be using an old version of the firmware. Policy Rules was replaced by VPN Director some time ago.
I've read this about 20 times and I still can't work out what "it" is having the problem.I can get to it no problem with All instead of Policy Rules, but with it set that way if the VPN goes down it uses my regular internet instead of just thinking there is NO internet like it does with Policy Rules (which is what I want).
Sorry I was not clear the issue is I can't get to the routed device ie 192.168.25.100 when it is set to Policy Rules but I can get to it if, it is set to All, and I want to use Policy Rules, but I can't figure out why the "route 192.168.25.100 255.255.255.255 vpn_gateway" does not work when it is set to Policy Rules. Sorry and it is "Redirect Internet traffic".I've read this about 20 times and I still can't work out what "it" is having the problem.
Are you saying this problem only happens when you have the "route" command present in your custom configuration?
Is "it" the router? So you're saying that "Block routed clients if tunnel goes down" is not working when Policy Rules are not being used? This seems to be the opposite of what you said in post #1.
route 192.168.25.100 255.255.255.255 vpn_gateway
line at all? Well if I take out "route 192.168.25.100 255.255.255.255 vpn_gateway" it does not connect on All or Policy Rules, but with it in I can get to it on All but not Policy Rules.Do you need theroute 192.168.25.100 255.255.255.255 vpn_gateway
line at all? As far as I can see that would only be required if the device at 192.168.25.100 wanted to initiate a connection back to your router.
See the edit to my previous post.Well if I take out "route 192.168.25.100 255.255.255.255 vpn_gateway" it does not connect on All or Policy Rules, but with it in I can get to it on All but not Policy Rules.
Yes 192.168.25.0/24 is definitely the server side of the tunnel and no there is nothing unusual happening on it.See the edit to my previous post.
Can you confirm that 192.168.25.0/24 is the network on the server side of the tunnel? Is there any unusual routing happening on the remote network?
ip rule
ip route show table main
ip route show table ovpnc1
Ok well thanks for trying to help anyway, I appreciate your time. these are the logs when Policy Rules is on...Sorry, I'm out of ideas. I don't have any way of testing this and in any case the implementation of policy rules has changed over time.
You could try looking at the output of these commands and comparing them with and without policy rules.
Code:ip rule ip route show table main ip route show table ovpnc1
Ok well here is the output of those commands...Sorry, I'm out of ideas. I don't have any way of testing this and in any case the implementation of policy rules has changed over time.
You could try looking at the output of these commands and comparing them with and without policy rules.
Code:ip rule ip route show table main ip route show table ovpnc1
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!