What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

VPNDirector (VPN sequence)

Jetblue

Occasional Visitor
I am using the RT-AX88U-Pro on 3004.388.8.4 firmware, successfully using Wireguard (WG) with the VPN Director. I connected to 2 VPN locations (Toronto & Dallas), and I connect to Dallas in my VPN Director, all working fine. The documentation instructs that for a VPN Kill Switch, do not apply it to the first VPN connection, but to the second. This seems to make sense, I assume that if the first VPN connection loses connectivity, then it fails over to the second VPN connection e.g.;

Choice 1. VPN Dallas ---> Initial connection in VPN Director
Choice 2. VPN Toronto ---> warm connection (kill switch is here)

All seems well with this, however in the actual Wireguard Clients (WGC1-5) list (see below), they are in no particular order. Do the Wireguard Cients (WGC) need to be "in matching order" for the failover to work? See the screenshot below. Do I need to move Toronto down beneath Dallas for the failover to work properly?

1750347311839.png
 
Last edited:
The rules govern, not the order of the clients. It looks like your rules say, seven devices go over WAN, and everything else to anywhere goes over Dallas. Nothing ever to Toronto. Also, you have two local subnets-xx.xx.50.xx and xx.xx.53.xx?
 
Also, you have two local subnets-xx.xx.50.xx and xx.xx.53.xx?
@Jetblue appears to have three subnets.
What I assume is the main LAN subnet: 192.168.50.x
Followed by what I assume are two Guest Network Pro subnets: 192.168.52.x and 192.168.53.x.
 
The rules govern, not the order of the clients. It looks like your rules say, seven devices go over WAN, and everything else to anywhere goes over Dallas. Nothing ever to Toronto. Also, you have two local subnets-xx.xx.50.xx and xx.xx.53.xx?
Yes, the seven devices shown are going over WAN to bypass the VPN, and everything else goes through the Dallas WGC initially.
Some of those devices are on Guest Networks (VLAN) so the IP's are a little different.

So if the rules govern... and Dallas WGC goes down, does the VPN director just randomly choose another Wireguard Client from the list? No order?
 
In addition to the VPN Director Priority link posted by ColinTaylor, see this discussion:
Edit to add: There are also several VPN addon scripts for Asus-Merlin that may be relevant:
 
See the wiki (I think that answers your question):
So, I followed the Wiki and sure enough it automatically orders the WGC clients in the rules, based on the Wireguard VPN drop down. You can see below. And just as the Wiki says, it is now using my Failover choice (Toronto) as the primary. Not a huge deal, it means that I have go through, delete all of my Wireguard entries an re-enter them in the order where my Primary (Dallas) is the first choice in the dropdown. It's obvious here that this is a great improvement that could be made in future versions, so that these could be easily re-ordered (versus deleting everything out and re-entering each time). See below.

1750383719780.png


The above is from the VPN Client Tab. Below is the result in the VPN Director. Pretty important to know this BEFORE you put all of the WGC clients into the router. Below is the VPN Director;

1750383826757.png
 
Last edited:
In addition to the VPN Director Priority link posted by ColinTaylor, see this discussion:
Edit to add: There are also several VPN addon scripts for Asus-Merlin that may be relevant:
Thanks bennor.
This link is great... He says it right there. Bingo.

"If OpenVPN client #1 fails, it automatically falls through to OpenVPN client #2. If OpenVPN client #1 eventually recovers, it will automatically return to OpenVPN client #1. That's just the wait it works."

All good. He forgot to say "JUST MAKE SURE YOU ENTER THEM IN THE CORRECT PRIORITY IN YOUR VPN WIREGUARD DROP DOWN BOX OR YOU WILL HAVE DELETE THEM ALL AND START OVER!"

Thanks for the confirmation. I'm going to take the router offline and re-configure/re-order all of the Wireguard connections manually.
 
You could simplify your rules a bit by grouping devices into smaller subnets, and then doing a rule for the subnet.

I suspect you could avoid having to redo your configs by just renaming the config files with ssh.

The simplification and control offered by VPN Director are a truly stellar feature.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top