Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple Openvpn clients, route specific IPs

    OpenVPN
    3
    3
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      joelones
      last edited by

      Probably a simple feat but I cannot get this to work.

      I am connected to two different vpn servers with a third party provider. Under Firewall->NAT->Outbound I have selected "Automatic outbound NAT rule generation" first, then "Manual Outbound NAT rule generation" and noticed the the default mappings for each of my interfaces (WAN, VPN1, VPN2).

      I'd like to direct certain private addresses out one VPN and certain out another. Not sure sure how to accomplish this, all traffic is going out the first VPN connection even though there's mapping for the WAN interface proceeding it. Doesn't the order matter? Am I missing something.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        The NAT doesn't actually make anything route to/through it, it just makes NAT happen if a packet/flow does go that way.
        You will want rules on LAN that select particular source IPs and select the gateway they are to use in the firewall rule advanced settings section. If you want failover or loadbalancing, then create gateway groups with multiple gateways in them and use the rules to feed traffic into gateway groups.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • ?
          A Former User
          last edited by

          You got a Multi GW setup for this ?

          If so, simply use a firewall rule to do this… like this here:

          Set the GW as required

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.