Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Want to Block 1IP from using Internet when VPN goes down

    Scheduled Pinned Locked Moved Firewalling
    55 Posts 4 Posters 12.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      If you don't want traffic from 192.168.0.11 to go out WAN at all, why are you policy routing it out WAN?

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • C
        comet424
        last edited by

        if your talking about from the picture above the 2nd from the bottom
        i dont... but if i dont put that rule in there... and i turn off both VPN's
        the rules skip the 2 rules below Game Consoles and goes straight to the last Line..

        so i put rule just above it... and its TAG No WAN EGRESS so it blocks using WAN

        1 Reply Last reply Reply Quote 0
        • C
          comet424
          last edited by

          figured that was better then saying Block 192.168.0.11 * * * in the rules
          unless thats better then the TAG i just figured it was a better block if not ill change it

          1 Reply Last reply Reply Quote 0
          • C
            comet424
            last edited by

            is this more proper thenblock wan.JPG

            1 Reply Last reply Reply Quote 0
            • C
              comet424
              last edited by

              @Derelict
              I have 1 more question if you might know..
              the no_wan_egreess works as long as my vpn I don't check the box "Don't Pass Routes"
              if I enable it... The IP Address I have Tag NO WAN EGRESS is automatically blocked yet should be using the VPN

              but I notice I need to check Don't Pass Routes to get my XBOX to work bypass VPN

              do you know how to get get the rule to work for the VPN and TAG No Wan Egress when you check "Don't Pass Routes"

              and should I be using that check box or not... whats the difference I tried googling info but I didn't find info
              if you have a link that explains the 2 be good too

              but I figured I ask you about that since your very smart at this stuff

              1 Reply Last reply Reply Quote 0
              • C
                comet424
                last edited by

                so having the check mark Dont Pass Routes... still leaks dns yet i dont see it...

                i get email from my isp i done suspicious things but i didnt
                i run www.dnsleaktest.com on the 192.168.0.11 and it shows 1 server my NordVPN
                yet it must be leaking

                is there another program that runs on windows that securly checks this stuff?
                as this No Wan Egress isnt working
                least it seems to work only when "DO Not Pull Routes" is not Checked.
                when its checked it seems to leak or not work right

                is there a way to test this and i read some articles you want Do Not Pull Routes other times you do .. how do you know when

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  I'm not sure that people appreciate how complicated what you are trying to do is.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • C
                    comet424
                    last edited by

                    sorry then ill figure out myself

                    didnt think it was complicated for you guys just for me
                    cuz i guess it works fine if Do not pull routes... yet XBOX doesnt work for OPen Nat
                    and when i do check off pull routes No WAN Gress does not kick in instantly like it does when "do not pull routes " is not checked... and Xbox Works Open Nat

                    very sorry for troubling you guys then.. i wont ask again

                    have a good weekend

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      It's not complicated for me. It would just take me three hours I don't have to explain it to you.

                      You need to understand:

                      • Policy routing and what it is and is not
                      • The routing table and what it is and is not
                      • What Don't pull routes actually does with your chosen VPN provider
                      • How DNS actually works
                      • How connections originating from the firewall itself apply in all of the above
                      • How tagging and matching tagged in pf works

                      I suggest watching https://www.youtube.com/watch?v=lp3mtR4j3Lw

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Think you forget the 0 on your 3 there Derelict... Your 4 days in already.. ;)

                        This is clearly simple facebook sort of post -- suggest you get your help over there since you don't seem to want to take Derelicts ;) Sure they help you out in couple of mins..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.