<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Policy Based Routing]]></title><description><![CDATA[<p dir="auto">Just created a couple of NordVPN OpenVPN tunnels and set up a Gateway group.</p>
<p dir="auto">Am I correct in stating my non VPN routed networks needs to be set up like this:-</p>
<p dir="auto"><img src="/assets/uploads/files/1549021753165-screenshot-2019-02-01-at-11.42.54-resized.png" alt="0_1549021752698_Screenshot 2019-02-01 at 11.42.54.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Where h_ip_local = my local subnets excluding the Nord routed network.</p>
<p dir="auto"><img src="/assets/uploads/files/1549021827666-screenshot-2019-02-01-at-11.47.30-resized.png" alt="0_1549021827444_Screenshot 2019-02-01 at 11.47.30.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Everything seems to be working fine, first go at multi WAN &amp; policy based routing :)</p>
]]></description><link>https://forum.netgate.com/topic/140192/policy-based-routing</link><generator>RSS for Node</generator><lastBuildDate>Thu, 12 Mar 2026 00:54:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/140192.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 Feb 2019 11:51:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Policy Based Routing on Sat, 02 Feb 2019 20:47:19 GMT]]></title><description><![CDATA[<p dir="auto">You essentially have two choices when dealing with an OpenVPN provider "WAN."</p>
<ol>
<li>
<p dir="auto"><strong>DO NOT</strong> check <em>Don't pull routes</em> in the OpenVPN client configuration and policy route the traffic you <strong>DO NOT WANT</strong> to go over the VPN.</p>
</li>
<li>
<p dir="auto"><strong>DO</strong> check <em>Don't pull routes</em> in the OpenVPN client configuration and policy route the traffic you <strong>DO WANT</strong> to go over the VPN.</p>
</li>
</ol>
<p dir="auto">I generally prefer option 2 but that presents problems if you do not understand the ramifications of the fact that <strong>connections originating FROM THE FIREWALL ITSELF cannot easily be policy routed</strong>.</p>
]]></description><link>https://forum.netgate.com/post/821845</link><guid isPermaLink="true">https://forum.netgate.com/post/821845</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Sat, 02 Feb 2019 20:47:19 GMT</pubDate></item></channel></rss>