Disable VPN Traffic over my network

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
macrodesk1
DD-WRT Novice


Joined: 30 Aug 2019
Posts: 1

PostPosted: Mon Jan 30, 2023 6:20    Post subject: Disable VPN Traffic over my network Reply with quote
How to prevent anyone to use any VPN software in their PC or device on top of my network using DD-WRT? How to identify the traffic whether it's a if using port 443 since I don't want to disallow port 443, but only the VPN.
Sponsor
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6435
Location: UK, London, just across the river..

PostPosted: Mon Jan 30, 2023 10:17    Post subject: Reply with quote
The only way known to me to prevent VPN traffic..is to block the range of IP's related to the VPN..so,
the clients will not be able to establish communication...and this is almost impossible with consumer grade routers...as you need to find all the servers and ect...speaking of kids its a Cats and Dogs game...
If you block one, they will go to another and so on....you wont believe..but..kids are crafty this days... Laughing Laughing you can only cut their internet time based and impose a serious restriction rules via iptables/ipset rules, but this need a high grade consumer class router..that supports IPset and iptables -m time module... (for example Netgear R7800 or R9000)...
For more on IPset https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327261 have a good read on the egc guide

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55779 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2963
Location: Germany

PostPosted: Mon Jan 30, 2023 11:01    Post subject: Reply with quote
Doesn't China do that somehow with deep packet inspection?
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12875
Location: Netherlands

PostPosted: Mon Jan 30, 2023 11:04    Post subject: Reply with quote
Another approach might be the use of ndpi (deep packet inspection), not sure if this works.
Under Acces restriction/ Blocked services.

But I have no experience with it.

Even if this works the VPN scramble option is able to circumvent this.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6435
Location: UK, London, just across the river..

PostPosted: Mon Jan 30, 2023 19:46    Post subject: Reply with quote
I didn't mention ndpi as back in the days it was very CPU consuming....especially on heavy traffic it overwhelms the router...there was an update recently...may be its improved...try it...
it may work..in fact DDWRT needs some users to try this and that... Wink

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55779 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum