Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Private internet access VPN

    Scheduled Pinned Locked Moved OpenVPN
    10 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MadMan3353
      last edited by

      I set two alias groups since they are on different networks and need to prevent them from accessing the VPN. Can anyone tell me how to block alias from accessing the PIA network? I was able to successfully set up PIA to route all traffic via the VPN however i need specific host's to not access it since they use their own VPN's for work. Is there a simple way of doing this?

      M 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        Firewall rules above the rule that routes everything out your PIA Gateway:-

        Screenshot 2021-11-01 at 19.37.08.png

        Everything except 172.16.9.14 routes out via NORD gateway.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        M 1 Reply Last reply Reply Quote 0
        • M
          MadMan3353 @MadMan3353
          last edited by

          @madman3353
          With this set up i was trying to route the noVPN rule so that the alias assigned would not go through PIA however those clients are still going through the VPN. any suggestions on how to fix?

          d09a75bc-4ae3-4aea-b2fb-6d700cad3c85-image.png
          0d5818b9-b310-4351-9c23-f180a0b078aa-image.png

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @MadMan3353
            last edited by NogBadTheBad

            @madman3353 Rules are read from the top down, also remember to reset your firewall states.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            M 1 Reply Last reply Reply Quote 0
            • M
              MadMan3353 @NogBadTheBad
              last edited by

              @nogbadthebad are you able to expand that rule so i can see the option chosen?

              1 Reply Last reply Reply Quote 0
              • M
                MadMan3353 @NogBadTheBad
                last edited by

                @nogbadthebad
                like this?
                13728104-1238-4943-8874-510184d1f031-image.png

                4dfec47c-7aa0-4984-a849-c4b7a9c2e0c6-image.png

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @MadMan3353
                  last edited by NogBadTheBad

                  @madman3353

                  Screenshot 2021-11-01 at 19.43.18.png

                  Screenshot 2021-11-01 at 19.43.37.png

                  Screenshot 2021-11-01 at 19.43.46.png

                  Copy your rule that forces traffic down your PIA, change the source to the ip addresses you dont want to route out the PIA and change the gateway to the default.

                  Then place the rule above the PIA rule, then reset the firewall states.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    MadMan3353 @NogBadTheBad
                    last edited by MadMan3353

                    @nogbadthebad your n.ipv4.local is that you local address?

                    not sure what to put here on my destination address. the no_VPN has a list of IPs

                    Thank you for the assist btw.

                    f9504431-452b-43da-a341-1773a1562cbf-image.png

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @MadMan3353
                      last edited by

                      @madman3353 I use an alias n_ipv4_local that contains my local IPv4 addresses, its basically saying allow internet only.

                      You could untick the invert and have any.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        MadMan3353 @NogBadTheBad
                        last edited by

                        @nogbadthebad amen brother that worked thank you. not the wife can work and stop giving me the side eye as to why the network is going up and down..lol

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.