To VPN or not to VPN

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
ChristianNO
DD-WRT Novice


Joined: 05 Aug 2014
Posts: 22

PostPosted: Fri Nov 26, 2021 17:52    Post subject: To VPN or not to VPN Reply with quote
Right now Ibhave a network with a R8000 as Internet router and two R7000
as sattelite APs.

The R8000 has a VPN to HMA for antigeoblocking TV.

But I also need no VPN for lokal TV. Some years ago I routed the relavant
networks around the VPN which…since spreading of amazon cloud works
any longer. Right now I‘m stopping the VPN on demand.

Now I‘m searching for a more clever solution.

My thoughts are to use one of the sattelite-APs and it‘s different Wifi-Interfaces.

The idea is for example the everything that comes over 5G should go into VPN.
Everything that comes in with the 2.4G won‘t go into the VPN.

This would make it possible just to switch the SSID on the Apple TV to choose
between VPN and not to VPN on the other SSID without logging into the R8000
to stop the VPN.

Is this possible to configure?

the local 192.168.x.x network needs to be available for HomeKit-purpos.

Regards

Christian
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12917
Location: Netherlands

PostPosted: Fri Nov 26, 2021 18:36    Post subject: Reply with quote
You can do that with Policy Based Routing.
You route certain IP addresses or whole interfaces via the VPN.
Everything else not

See the VPN guides:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
ChristianNO
DD-WRT Novice


Joined: 05 Aug 2014
Posts: 22

PostPosted: Sat Nov 27, 2021 9:50    Post subject: Reply with quote
Certain Ips won’t solve the request since the IP won‘t change if you change
between wl0 to wl1.

The only solution will be if all traffic that comes in via wl0 goes into the VPN
and all that comes in via wl1 does not go into the VPN.

The IP won‘t change since the R7000/AP is not the source for DHCP, the R8000 is.


Last edited by ChristianNO on Sat Nov 27, 2021 18:23; edited 2 times in total
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12917
Location: Netherlands

PostPosted: Sat Nov 27, 2021 10:01    Post subject: Reply with quote
You have to use unbridged vap's and do not NAT on the R7000 but use static routing Smile
_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum