Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How do I force all internet through the VPN tunnel?

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 3 Posters 352 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      billsecond
      last edited by

      Hello, I have a peer to peer VPN set up in my SG-1100 (Netgate) firewall. I am trying to get it so that all of my network traffic (0.0.0.0/0) goes through the VPN tunnel when connected.

      I have tried so many different things, but nothing seems to work.

      1 Reply Last reply Reply Quote 0
      • Y
        yumcheese
        last edited by

        You might want to paste some route info. (Diagnostics | Routes). Sounds like you have to change your default route somehow to go through the Openvpn tunnel instead of the WAN. What have you tried so far?

        1 Reply Last reply Reply Quote 0
        • M
          marvosa
          last edited by marvosa

          On your end, you have to assign the tunnel to an interface, which creates a gateway. Then policy route your traffic over the tunnel via firewall rules that leverage the gateway that was created in the first step.

          On the remote end, there needs to be a NAT entry for your LAN subnet.

          B 1 Reply Last reply Reply Quote 0
          • B
            billsecond
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • B
              billsecond @marvosa
              last edited by

              @marvosa said in How do I force all internet through the VPN tunnel?:

              On your end, you have to assign the tunnel to an interface, which creates a gateway. Then policy route your traffic over the tunnel via firewall rules that leverage the gateway that was created in the first step.

              On the remote end, there needs to be a NAT entry for your LAN subnet.

              Thanks, what side is my side, and what side is the remote side?
              Also, how do I do a Policy route?

              1 Reply Last reply Reply Quote 0
              • M
                marvosa
                last edited by marvosa

                Well, the topic is "How do I force all internet through the VPN tunnel?", so my assumption is you want internet traffic on your LAN forced thru a VPN tunnel, correct? If so, your end is the local end and the network behind the VPN is the remote (or far) end.

                how do I do a Policy route?

                1. Assign the VPN to an interface.
                2. On the LAN tab, create a firewall rule (above your LAN net/any rule) that has:
                  a. Protocol = any
                  b. Source = specify your LAN subnet or choose "
                  c. Destination = any
                  d. Gateway = The gateway IP created from assigning the VPN to an interface (This is done by expanding the "Advanced Options" section)
                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.