What's new

VPN tunneling for torrent only with Kill Switch capabilities

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Totojet81

New Around Here
Hello everybody,

New on this community and hope to find a solution to my problem. I'm not an expert in network but I will try to explain my wish the best I can.

My setup in very simple:
- An Asus RT-AX58U (sadly v2 so no Merlin FW...) used to replace my ISP garbage device;
- A Synology NAS DS220j (j series so no docker possible...);
- A paid VPN account successfuly setup but not connected at this time on my routeur and my NAS;

I would like, as a lot of people, use my VPN connection only for torrent download (with kill switch capabilities) and leave others applications/services use the default WAN. However, due to my technical (and knowledge) limitations (no Merlin, no Docker...) I have a lot of difficulties to make it work...

The "best" solution I achieved is to setup the VPN on my Synology NAS, activate the "Multiple Gateway" option. I always can access remotly to my NAS which is a very good point, however the complete traffic from/to my NAS is passing by the VPN.. Not satisfying for me.
Another solution would be to setup my Asus routeur to use the VPN connection for the whole NAS device, same problem : the complete traffic from/to my NAS is passing by the VPN and in addition I cannot access my NAS remotly.

I tried to deal with firewall rules on my router to block everything for my NAS (except VPN connection ports, remote NAS port connection and TCP port on my torrent client (Download Station provide by Synology : port 16881) to force it to use its VPN interface but without success, I don't know how it is possible but IP torrent checker always shows my real IP address...

I saw a lot of help/messages/documentations, but I'm always asking myself if it'll fit with what I want to achieve. I'm open to technical solution that ask to buy a V1 of my actual version for instance.

Don't hesitate to ask if you need more details.

Thank you !
 
Hello everybody,

New on this community and hope to find a solution to my problem. I'm not an expert in network but I will try to explain my wish the best I can.

My setup in very simple:
- An Asus RT-AX58U (sadly v2 so no Merlin FW...) used to replace my ISP garbage device;
- A Synology NAS DS220j (j series so no docker possible...);
- A paid VPN account successfuly setup but not connected at this time on my routeur and my NAS;

I would like, as a lot of people, use my VPN connection only for torrent download (with kill switch capabilities) and leave others applications/services use the default WAN. However, due to my technical (and knowledge) limitations (no Merlin, no Docker...) I have a lot of difficulties to make it work...

The "best" solution I achieved is to setup the VPN on my Synology NAS, activate the "Multiple Gateway" option. I always can access remotly to my NAS which is a very good point, however the complete traffic from/to my NAS is passing by the VPN.. Not satisfying for me.
Another solution would be to setup my Asus routeur to use the VPN connection for the whole NAS device, same problem : the complete traffic from/to my NAS is passing by the VPN and in addition I cannot access my NAS remotly.

I tried to deal with firewall rules on my router to block everything for my NAS (except VPN connection ports, remote NAS port connection and TCP port on my torrent client (Download Station provide by Synology : port 16881) to force it to use its VPN interface but without success, I don't know how it is possible but IP torrent checker always shows my real IP address...

I saw a lot of help/messages/documentations, but I'm always asking myself if it'll fit with what I want to achieve. I'm open to technical solution that ask to buy a V1 of my actual version for instance.

Don't hesitate to ask if you need more details.

Thank you !

Does your NAS have a second ethernet port, or a way to assign a second IP to the main port? Then you bind your VPN client to one of those and the other is used for non-VPN management/NAS access. Or run the VPN on the Asus and allow the second (management) IP to bypass it, and make sure your torrent client is bound to the first one.

Only other thing I can think is to exclude the ports for management traffic from the VPN, but not sure if any of the VPN clients on these boxes will let you specify IP and ports.

Firewall isn't the place to do it, that isn't tied to the VPN.

If all else fails, use a PC or some other dedicated device with dedicated IP for torrenting which makes it easy to set up the VPN rules.
 
Thank you for your reply, unfortunately my NAS has only one ethernet port. And no such customization are possible on the VPN interface from the NAS...

I am starting to consider the option to replace my DS220j by a DS220+ to be able to virtualize and then setup the VPN client within the Docker.
 
Thank you for your reply, unfortunately my NAS has only one ethernet port. And no such customization are possible on the VPN interface from the NAS...

I am starting to consider the option to replace my DS220j by a DS220+ to be able to virtualize and then setup the VPN client within the Docker.

Does it support VLANs? If so you could create a second VLAN and run a script on the asus to accept that VLAN. Getting a bit more advanced there though, and that still assumes the VPN client can be bound to the VLAN sub-interface.

Rather than replace the NAS why not look at a little x86 micro PC or even potentially Raspberry pi for a dedicated torrent box? It is sort of the thing I personally want on a separate isolated machine. Mine is on an old laptop in a guest network, and is a machine I use for that and doing other things that I feel are more "risky". I just run a VPN client right on that PC since I don't do that much torrenting.
 
I haven't see some VLAN options with the VPN client configuration on my NAS.

Using a Pi to download only could be an option but I won't be able to start torrent remotely as I don't want to open additional ports on my router more than the NAS DSM port which redirects to a strong auth system (login:password + 2FA). With a Docker on my NAS I'll be able to trig/manage torrent through Deluge with a Telegram bot (it's my more recent idea for now...).

I admit it, I don't download that much but love those technical stuffs and having a bettter NAS with virtualization option could be great :)
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top