Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Selective routing not working

    Scheduled Pinned Locked Moved OpenVPN
    26 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by

      Well you have traffic flowing via your WAN_DHCP Gateway, it shows 4.59 GiB for GamingIPS.
      What exactly is the problem?

      -Rico

      1 Reply Last reply Reply Quote 0
      • MichaelSmithM
        MichaelSmith
        last edited by

        Well when I try to download a game through steam which gaming ips is all of steams URLs it still uses the VPN or when I go on Netflix it still says I'm using a proxy

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          Check the States an if the Steam IP is in your Alias or not, maybe you are missing something there.

          -Rico

          1 Reply Last reply Reply Quote 0
          • MichaelSmithM
            MichaelSmith
            last edited by

            I do I even got a test one set up to avoid vpn but whever I go on speed test it still shows vpn ip009df0143fb10884dbb4e391d00e3d7c.png

            1 Reply Last reply Reply Quote 0
            • MichaelSmithM
              MichaelSmith
              last edited by

              you see when I download somthing it all goes through the VPN25a6313698178a63f1f9076c14a4ac30.png

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by Rico

                A proper whitelisting is much harder then just put the website URL into some Alias...
                For example, the IP for speedtest.net has zero to with the target IP of the server which is performing the speedtest. Let's see...

                nslookup speedtest.net
                
                Name:    speedtest.net
                Addresses:  
                          151.101.194.219
                          151.101.2.219
                          151.101.66.219
                          151.101.130.219
                

                Now let's do the speedtest and check which IP we hit.
                speedtest.net.png

                The problem is, of course we could just add 185.60.197.7 into our Alias...but the next speedtest would probably hit any other IP.
                If the website owner has no public documentation of all IP ranges they use it is almost impossible to catch alle their servers.

                -Rico

                MichaelSmithM 1 Reply Last reply Reply Quote 0
                • MichaelSmithM
                  MichaelSmith @Rico
                  last edited by MichaelSmith

                  @Rico I understand your point for speed test however why does it not work for ports and steam as that is done through DNS

                  like why is 100% of my traffic going through the VPN when I look at the graphs

                  1 Reply Last reply Reply Quote 0
                  • RicoR
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    Show your Port alias and states so we can check.

                    -Rico

                    MichaelSmithM 1 Reply Last reply Reply Quote 0
                    • MichaelSmithM
                      MichaelSmith @Rico
                      last edited by MichaelSmith

                      @Rico Sure63654d9301a20471827cab964fac7152.png 12a56b7b9d0b6fea2bea028bb7ebc6c5.png
                      c7d302cdb0445b195ee132015f925b8d.png

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by

                        This does not look like a big download and is mostly https (443) traffic not hitting your Rule.

                        -Rico

                        MichaelSmithM 1 Reply Last reply Reply Quote 1
                        • MichaelSmithM
                          MichaelSmith @Rico
                          last edited by

                          @Rico so what should I do add port 80 adnd 443 to the rule ?

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            Here is a (hopefully) complete list containing all Valve Servers: https://bgp.he.net/AS32590#_prefixes
                            Create an Alias for it with all Prefixes and move the Firewall Rule on top, delete your other Rules.

                            -Rico

                            MichaelSmithM 1 Reply Last reply Reply Quote 1
                            • MichaelSmithM
                              MichaelSmith @Rico
                              last edited by MichaelSmith

                              @Rico Yeah About that my pfsense kinda crashed after I put it all in cus theres a limit of 5000 hosts per alias but thats far more I mean the first 10 ips hit that limit and theres 30 so ill need to make like 6 aliases for it

                              1 Reply Last reply Reply Quote 0
                              • RicoR
                                Rico LAYER 8 Rebel Alliance
                                last edited by Rico

                                You add the networks as they are reported in the List, not single host.

                                Steam_networks.png

                                -Rico

                                MichaelSmithM 2 Replies Last reply Reply Quote 0
                                • MichaelSmithM
                                  MichaelSmith @Rico
                                  last edited by

                                  @Rico said in Selective routing not working:

                                  add the networks as they are reported in

                                  Hahah no wonder were running out of IPv4 when companies like steam are ussing them like internal Ips

                                  1 Reply Last reply Reply Quote 0
                                  • MichaelSmithM
                                    MichaelSmith @Rico
                                    last edited by MichaelSmith

                                    @Rico oh my gosh thank you so much it now bypasses steam and the downloads are rapid, So to do this bypass for netflix would I need to find their Ips aswell ?

                                    Cus they got allot more some Ipv6 do you know a fast way to import them ?

                                    also how can I check if my port bypasses are working and some games use 80 and 443 as there ports so how would I vpn bypass those without literally vpn bypassing every site?

                                    sorry for so many questions and thanks for the help

                                    8a97190fd50910b0ff85463c478505ac.png

                                    ae40025c13f000cf9e79d99bb9037ca2.png

                                    1 Reply Last reply Reply Quote 0
                                    • RicoR
                                      Rico LAYER 8 Rebel Alliance
                                      last edited by Rico

                                      Well you can also use the import function.
                                      Alias_Import.png

                                      Port 80 and 443 is http and https, not possible to exclude only games by these ports.
                                      Depending on the goal you try to accomplish, maybe it is better and even easier to build the setup to have your WAN_DHCP as default and create the Rules for stuff you want to send out via VPN?

                                      -Rico

                                      MichaelSmithM 1 Reply Last reply Reply Quote 0
                                      • MichaelSmithM
                                        MichaelSmith @Rico
                                        last edited by

                                        @Rico Yeah I agree however what I want to use the VPN is torrenting and web browsing so it easier to bypass other things rather than chose the ones I want

                                        1 Reply Last reply Reply Quote 0
                                        • RicoR
                                          Rico LAYER 8 Rebel Alliance
                                          last edited by

                                          Hmmm personally I would never send out any of my Web traffic through some VPN provider.
                                          For example, if I login to my bank account, Paypal or even stuff like amazon...I don't want to send this kind of traffic to any third parties even if it is encrypted.

                                          -Rico

                                          MichaelSmithM 1 Reply Last reply Reply Quote 1
                                          • MichaelSmithM
                                            MichaelSmith @Rico
                                            last edited by

                                            @Rico said in Selective routing not working:

                                            gin to my bank account, Paypal or even stuff like amazon...I don't want to send this k

                                            Yeah thats true

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.