I have been researching the use of VPN to protect my internet use and have decided to go with PrivateInternetAccess. I want to setup the VPN on my router to protect all my devices but before I commit can anyone tell me if there is a way to exclude certain web addresses and local IP addresses from connecting via the VPN. I am concerned that my online banking may be an issue connecting from a non UK IP address and also I want my company laptop not to use the VPN.
Several posters on this site have written scripts which may provide a framework for accomplishing what you want.
Another option is to look at the self installing Astrill application on routers running Merlin's firmware. Beware that there are problems challenges as DNS doesn't always resolve the way you anticipated.
The most elegant and perhaps most expensive is to run Sabai's dual gateway software that runs on several different router models that Sabai sells with the software preinstalled. The price may look high, but the support that Sabai offers is in my opinion is worth every cent. Sabai's firmware supports a number of VPN providers including the one you selected.
Finally the simplest and least expensive might be to install your VPN on your primary router then take another router and double NAT it behind the primary router and have your company PC connect to the secondary router. You may have to reverse the order and have your first/primary router connect directly to your local ISP and then run your VPN on your secondary router that is double NATed behind the first router. That is my set up. I have two VPN routers double NATed behind my primary Actiontec router from FIOS.
Thanks for the info. I was hoping there was a way to configure this within the GUI, maybe this could be added in a later version. Would be great to be able to select individual router LAN ports or IP addresses to work over the VPN and everything else to go via the ISP.
I will look into setting up a secondary router and double NATing, I have a Dlink router I may be able to use.
...don't know if this will work that way, but what about using the guest-SSID for the company laptop (you will get internet access only, no access to local ressources) but IMHO this also should bypass the VPN in the WAN side.