Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Selective routing not working

    Scheduled Pinned Locked Moved OpenVPN
    26 Posts 2 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by

      Please use the 'Upload Image' button.
      Most people includung me don't want to follow external unknown URLs...

      -Rico

      MichaelSmithM 1 Reply Last reply Reply Quote 0
      • MichaelSmithM
        MichaelSmith @Rico
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          Make sure to check the "Don't pull routes" Option in your OpenVPN Client Configuration.

          -Rico

          MichaelSmithM 1 Reply Last reply Reply Quote 0
          • MichaelSmithM
            MichaelSmith @Rico
            last edited by

            @Rico it is checkedF2222C0B-67ED-4864-AD58-A8B4F12A9B8D.png

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              Well you have traffic flowing via your WAN_DHCP Gateway, it shows 4.59 GiB for GamingIPS.
              What exactly is the problem?

              -Rico

              1 Reply Last reply Reply Quote 0
              • MichaelSmithM
                MichaelSmith
                last edited by

                Well when I try to download a game through steam which gaming ips is all of steams URLs it still uses the VPN or when I go on Netflix it still says I'm using a proxy

                1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by

                  Check the States an if the Steam IP is in your Alias or not, maybe you are missing something there.

                  -Rico

                  1 Reply Last reply Reply Quote 0
                  • MichaelSmithM
                    MichaelSmith
                    last edited by

                    I do I even got a test one set up to avoid vpn but whever I go on speed test it still shows vpn ip009df0143fb10884dbb4e391d00e3d7c.png

                    1 Reply Last reply Reply Quote 0
                    • MichaelSmithM
                      MichaelSmith
                      last edited by

                      you see when I download somthing it all goes through the VPN25a6313698178a63f1f9076c14a4ac30.png

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by Rico

                        A proper whitelisting is much harder then just put the website URL into some Alias...
                        For example, the IP for speedtest.net has zero to with the target IP of the server which is performing the speedtest. Let's see...

                        nslookup speedtest.net
                        
                        Name:    speedtest.net
                        Addresses:  
                                  151.101.194.219
                                  151.101.2.219
                                  151.101.66.219
                                  151.101.130.219
                        

                        Now let's do the speedtest and check which IP we hit.
                        speedtest.net.png

                        The problem is, of course we could just add 185.60.197.7 into our Alias...but the next speedtest would probably hit any other IP.
                        If the website owner has no public documentation of all IP ranges they use it is almost impossible to catch alle their servers.

                        -Rico

                        MichaelSmithM 1 Reply Last reply Reply Quote 0
                        • MichaelSmithM
                          MichaelSmith @Rico
                          last edited by MichaelSmith

                          @Rico I understand your point for speed test however why does it not work for ports and steam as that is done through DNS

                          like why is 100% of my traffic going through the VPN when I look at the graphs

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            Show your Port alias and states so we can check.

                            -Rico

                            MichaelSmithM 1 Reply Last reply Reply Quote 0
                            • MichaelSmithM
                              MichaelSmith @Rico
                              last edited by MichaelSmith

                              @Rico Sure63654d9301a20471827cab964fac7152.png 12a56b7b9d0b6fea2bea028bb7ebc6c5.png
                              c7d302cdb0445b195ee132015f925b8d.png

                              1 Reply Last reply Reply Quote 0
                              • RicoR
                                Rico LAYER 8 Rebel Alliance
                                last edited by

                                This does not look like a big download and is mostly https (443) traffic not hitting your Rule.

                                -Rico

                                MichaelSmithM 1 Reply Last reply Reply Quote 1
                                • MichaelSmithM
                                  MichaelSmith @Rico
                                  last edited by

                                  @Rico so what should I do add port 80 adnd 443 to the rule ?

                                  1 Reply Last reply Reply Quote 0
                                  • RicoR
                                    Rico LAYER 8 Rebel Alliance
                                    last edited by

                                    Here is a (hopefully) complete list containing all Valve Servers: https://bgp.he.net/AS32590#_prefixes
                                    Create an Alias for it with all Prefixes and move the Firewall Rule on top, delete your other Rules.

                                    -Rico

                                    MichaelSmithM 1 Reply Last reply Reply Quote 1
                                    • MichaelSmithM
                                      MichaelSmith @Rico
                                      last edited by MichaelSmith

                                      @Rico Yeah About that my pfsense kinda crashed after I put it all in cus theres a limit of 5000 hosts per alias but thats far more I mean the first 10 ips hit that limit and theres 30 so ill need to make like 6 aliases for it

                                      1 Reply Last reply Reply Quote 0
                                      • RicoR
                                        Rico LAYER 8 Rebel Alliance
                                        last edited by Rico

                                        You add the networks as they are reported in the List, not single host.

                                        Steam_networks.png

                                        -Rico

                                        MichaelSmithM 2 Replies Last reply Reply Quote 0
                                        • MichaelSmithM
                                          MichaelSmith @Rico
                                          last edited by

                                          @Rico said in Selective routing not working:

                                          add the networks as they are reported in

                                          Hahah no wonder were running out of IPv4 when companies like steam are ussing them like internal Ips

                                          1 Reply Last reply Reply Quote 0
                                          • MichaelSmithM
                                            MichaelSmith @Rico
                                            last edited by MichaelSmith

                                            @Rico oh my gosh thank you so much it now bypasses steam and the downloads are rapid, So to do this bypass for netflix would I need to find their Ips aswell ?

                                            Cus they got allot more some Ipv6 do you know a fast way to import them ?

                                            also how can I check if my port bypasses are working and some games use 80 and 443 as there ports so how would I vpn bypass those without literally vpn bypassing every site?

                                            sorry for so many questions and thanks for the help

                                            8a97190fd50910b0ff85463c478505ac.png

                                            ae40025c13f000cf9e79d99bb9037ca2.png

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.