<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I want to force the client to use its own internet gateway.]]></title><description><![CDATA[<p dir="auto">I want to force the client to use its own internet gateway. In my scenario, the client must definitely use its own internet. Some clients can send all traffic over VPN and the internet can be accessed through the VPN server's internet. I prevent this situation with security rules, but this time the internet cannot be accessed in any way. Even if routing is done to access the internet via VPN, my VPN server must not allow this and force it to use its own gateway. How do I do this?</p>
]]></description><link>https://forum.netgate.com/topic/187815/i-want-to-force-the-client-to-use-its-own-internet-gateway</link><generator>RSS for Node</generator><lastBuildDate>Sun, 15 Mar 2026 14:39:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/187815.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 28 Apr 2024 18:46:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I want to force the client to use its own internet gateway. on Fri, 03 May 2024 14:57:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/selcuk_ks">@<bdi>selcuk_ks</bdi></a> Do you mean force general internet traffic out the clients local gateway, and only all VPN for services you host ?<br />
If so, this is standard split tunnel, so un-select the "Force all traffic through tunnel"  option</p>
<p dir="auto"><img src="/assets/uploads/files/1714748201927-c2ef77b5-4e3b-4919-9504-7d2d4e23d0a3-image.png" alt="c2ef77b5-4e3b-4919-9504-7d2d4e23d0a3-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1166869</link><guid isPermaLink="true">https://forum.netgate.com/post/1166869</guid><dc:creator><![CDATA[pwood999]]></dc:creator><pubDate>Fri, 03 May 2024 14:57:07 GMT</pubDate></item><item><title><![CDATA[Reply to I want to force the client to use its own internet gateway. on Sun, 28 Apr 2024 19:21:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a> Thanks. I will try this when I have free time.</p>
]]></description><link>https://forum.netgate.com/post/1165877</link><guid isPermaLink="true">https://forum.netgate.com/post/1165877</guid><dc:creator><![CDATA[selcuk_ks]]></dc:creator><pubDate>Sun, 28 Apr 2024 19:21:52 GMT</pubDate></item><item><title><![CDATA[Reply to I want to force the client to use its own internet gateway. on Sun, 28 Apr 2024 19:19:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/selcuk_ks">@<bdi>selcuk_ks</bdi></a><br />
You VPN server do not have much impact on the clients routing table.<br />
You can push routes to the clients though, but this is nothing more than a recommendation in the end.</p>
<p dir="auto">So on the server just block any unwanted traffic from the client.</p>
<p dir="auto">Also you need an outbound NAT rule on WAN for the tunnel pool to masquerade the traffic with your WAN address. Without this, no internet access would be possible for the VPN clients.</p>
<p dir="auto">If pfSense has created the outbound NAT rule automatically, you can switch to hybrid mode and add a rule for the tunnel network and disable NAT inside it.</p>
]]></description><link>https://forum.netgate.com/post/1165876</link><guid isPermaLink="true">https://forum.netgate.com/post/1165876</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Sun, 28 Apr 2024 19:19:10 GMT</pubDate></item></channel></rss>