Policy Based Routing (OpenVPN)

Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> Advanced Networking
Author Message
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Wed Feb 28, 2024 23:11    Post subject: Policy Based Routing (OpenVPN) Reply with quote
I have some of this figured out but I haven't figured out how to get a port to bypass the VPN tunnel. When I add my box that contains the Postfix server in the PBR list, to route selected clients through the VPN, I can't send or receive e-mail. Strange thing is that I can telnet to it from another network and nmap shows the port open. Anyway, it's an openvpn issue since when I turn off the VPN I can send and receive email again. How do I route port 25 to outside of the VPN tunnel?
Sponsor
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14249
Location: Texas, USA

PostPosted: Thu Feb 29, 2024 0:13    Post subject: Reply with quote
Remove the server running Postfix from PBR...or set PBR to route IPs via WAN and not tunnel...
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Thu Feb 29, 2024 1:27    Post subject: Reply with quote
kernel-panic69 wrote:
Remove the server running Postfix from PBR...or set PBR to route IPs via WAN and not tunnel...

I run several items in the box, not just the postfix server. So, I want to route port 25 outside of the tunnel, not the IP assigned to the box. It's my understanding that it can be done but I don't know how.
bushant
DD-WRT Guru


Joined: 18 Nov 2015
Posts: 2037

PostPosted: Thu Feb 29, 2024 1:59    Post subject: Reply with quote
You can set PBR to "Route Selected Sources Via Wan"
then add
Code:
sport 25

in the PBR list

OpenVPN Client setup guide

_________________
Forum Guide Lines (with helpful pointers about how to research your router, where and what firmware to download, where and how to post and many other helpful tips!)
How to get help the right way

Before asking for help - Read the forum guidelines AND Upgrade DD-WRT!
Adblock by eibgrad (1.1M blocked) + Blocklist Collection

johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Thu Feb 29, 2024 16:09    Post subject: Reply with quote
bushant wrote:
You can set PBR to "Route Selected Sources Via Wan"
then add
Code:
sport 25

in the PBR list


Looks like I figured it out. The PBR selections had me confused since you can only select 1 of 3 options. Setting up my list in "Route Selected Sources Via Wan" was all I need to do. Everything else gets routed through the VPN. I get more dense the older I get. Thanks anyway. Anyway, I wish I could use wireguard with my VPN provider instead of OpenVPN. The VPN providers that I contacted didn't seem to want to provide a manual configuration for wireguard or they were using a proprietary form of wireguard (like NordLynx).
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Thu Feb 29, 2024 19:55    Post subject: Reply with quote
I guess I spoke too soon. I'm receiving incoming e-mail but outgoing email gets refused. Sending to other mailboxes on my system works OK though. If I disable the VPN the email goes out. Also, it turns out that my modifications prevent incoming WAN connections to my wireguard VPN from getting routed back out on the OpenVPN.
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6870
Location: Romerike, Norway

PostPosted: Fri Mar 01, 2024 10:22    Post subject: Reply with quote
Are you sure it's port 25. No email provider use port 25 anymore. That port is also blocked with most ISPs. Port 587 is used with TLS.
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Fri Mar 01, 2024 19:04    Post subject: Reply with quote
Per Yngve Berg wrote:
Are you sure it's port 25. No email provider use port 25 anymore. That port is also blocked with most ISPs. Port 587 is used with TLS.

Yes. Can't receive e-mail from the WAN without it. Anyway, the problem has been solved.
Mattithyahu
DD-WRT Novice


Joined: 21 May 2021
Posts: 8

PostPosted: Fri Apr 19, 2024 20:07    Post subject: Reply with quote
bushant wrote:
You can set PBR to "Route Selected Sources Via Wan"
then add
Code:
sport 25

in the PBR list

OpenVPN Client setup guide


Hi. I hope it's ok to hijack this thread. Creator said he fixed it, but did not tell what he did to achieve it.

I have WRT1200AC with build 55779.

I'm trying to forward a port 3456 with built-in PBR. I selected "Route Selected Sources Via Wan" option and wrote "sport 3456" in the box, but canyouseeme.org doesn't see my port.

If I write my PC IP into that box it bypasses VPN and canyouseeme.org sees my port, so I guess there is no firewall problem. It bypasses my PC, but not only 1 port.

I went to look at Routing Policy Table and I can see that port 3456 is directed to Table 10, so I guess the rule in PBR works.

I also tried to add Table 5 and Routing Policy for Table 5, according to https://forum.dd-wrt.com/phpBB2/download.php?id=48550 guide, but had no luck. I do see my forwarded port Routing Policy Table two times, on Table 5 (from guide) and 10 (from PBR).

Any idea what I'm doing wrong? Thank you!
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12920
Location: Netherlands

PostPosted: Sat Apr 20, 2024 6:54    Post subject: Reply with quote
@Mattithyahu please start your own thread, state router model and build number and describe your problem and what you want to achieve
_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   This topic is locked: you cannot edit posts or make replies.    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum