Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Selective routing not working

    Scheduled Pinned Locked Moved OpenVPN
    26 Posts 2 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MichaelSmithM
      MichaelSmith
      last edited by MichaelSmith

      This is my configuration however everything seems to go through the VPN and it doesnt avoid my preset destinations
      e1b2d9d7872a7381d8d01eb41a5d681a.png

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        Please use the 'Upload Image' button.
        Most people includung me don't want to follow external unknown URLs...

        -Rico

        MichaelSmithM 1 Reply Last reply Reply Quote 0
        • MichaelSmithM
          MichaelSmith @Rico
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            Make sure to check the "Don't pull routes" Option in your OpenVPN Client Configuration.

            -Rico

            MichaelSmithM 1 Reply Last reply Reply Quote 0
            • MichaelSmithM
              MichaelSmith @Rico
              last edited by

              @Rico it is checkedF2222C0B-67ED-4864-AD58-A8B4F12A9B8D.png

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by

                Well you have traffic flowing via your WAN_DHCP Gateway, it shows 4.59 GiB for GamingIPS.
                What exactly is the problem?

                -Rico

                1 Reply Last reply Reply Quote 0
                • MichaelSmithM
                  MichaelSmith
                  last edited by

                  Well when I try to download a game through steam which gaming ips is all of steams URLs it still uses the VPN or when I go on Netflix it still says I'm using a proxy

                  1 Reply Last reply Reply Quote 0
                  • RicoR
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    Check the States an if the Steam IP is in your Alias or not, maybe you are missing something there.

                    -Rico

                    1 Reply Last reply Reply Quote 0
                    • MichaelSmithM
                      MichaelSmith
                      last edited by

                      I do I even got a test one set up to avoid vpn but whever I go on speed test it still shows vpn ip009df0143fb10884dbb4e391d00e3d7c.png

                      1 Reply Last reply Reply Quote 0
                      • MichaelSmithM
                        MichaelSmith
                        last edited by

                        you see when I download somthing it all goes through the VPN25a6313698178a63f1f9076c14a4ac30.png

                        1 Reply Last reply Reply Quote 0
                        • RicoR
                          Rico LAYER 8 Rebel Alliance
                          last edited by Rico

                          A proper whitelisting is much harder then just put the website URL into some Alias...
                          For example, the IP for speedtest.net has zero to with the target IP of the server which is performing the speedtest. Let's see...

                          nslookup speedtest.net
                          
                          Name:    speedtest.net
                          Addresses:  
                                    151.101.194.219
                                    151.101.2.219
                                    151.101.66.219
                                    151.101.130.219
                          

                          Now let's do the speedtest and check which IP we hit.
                          speedtest.net.png

                          The problem is, of course we could just add 185.60.197.7 into our Alias...but the next speedtest would probably hit any other IP.
                          If the website owner has no public documentation of all IP ranges they use it is almost impossible to catch alle their servers.

                          -Rico

                          MichaelSmithM 1 Reply Last reply Reply Quote 0
                          • MichaelSmithM
                            MichaelSmith @Rico
                            last edited by MichaelSmith

                            @Rico I understand your point for speed test however why does it not work for ports and steam as that is done through DNS

                            like why is 100% of my traffic going through the VPN when I look at the graphs

                            1 Reply Last reply Reply Quote 0
                            • RicoR
                              Rico LAYER 8 Rebel Alliance
                              last edited by

                              Show your Port alias and states so we can check.

                              -Rico

                              MichaelSmithM 1 Reply Last reply Reply Quote 0
                              • MichaelSmithM
                                MichaelSmith @Rico
                                last edited by MichaelSmith

                                @Rico Sure63654d9301a20471827cab964fac7152.png 12a56b7b9d0b6fea2bea028bb7ebc6c5.png
                                c7d302cdb0445b195ee132015f925b8d.png

                                1 Reply Last reply Reply Quote 0
                                • RicoR
                                  Rico LAYER 8 Rebel Alliance
                                  last edited by

                                  This does not look like a big download and is mostly https (443) traffic not hitting your Rule.

                                  -Rico

                                  MichaelSmithM 1 Reply Last reply Reply Quote 1
                                  • MichaelSmithM
                                    MichaelSmith @Rico
                                    last edited by

                                    @Rico so what should I do add port 80 adnd 443 to the rule ?

                                    1 Reply Last reply Reply Quote 0
                                    • RicoR
                                      Rico LAYER 8 Rebel Alliance
                                      last edited by

                                      Here is a (hopefully) complete list containing all Valve Servers: https://bgp.he.net/AS32590#_prefixes
                                      Create an Alias for it with all Prefixes and move the Firewall Rule on top, delete your other Rules.

                                      -Rico

                                      MichaelSmithM 1 Reply Last reply Reply Quote 1
                                      • MichaelSmithM
                                        MichaelSmith @Rico
                                        last edited by MichaelSmith

                                        @Rico Yeah About that my pfsense kinda crashed after I put it all in cus theres a limit of 5000 hosts per alias but thats far more I mean the first 10 ips hit that limit and theres 30 so ill need to make like 6 aliases for it

                                        1 Reply Last reply Reply Quote 0
                                        • RicoR
                                          Rico LAYER 8 Rebel Alliance
                                          last edited by Rico

                                          You add the networks as they are reported in the List, not single host.

                                          Steam_networks.png

                                          -Rico

                                          MichaelSmithM 2 Replies Last reply Reply Quote 0
                                          • MichaelSmithM
                                            MichaelSmith @Rico
                                            last edited by

                                            @Rico said in Selective routing not working:

                                            add the networks as they are reported in

                                            Hahah no wonder were running out of IPv4 when companies like steam are ussing them like internal Ips

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.