VPN / Proxy Settings
-
I've got an IPTV service that I have subscribed to. However, it requires me to use a VPN because I'm in Canada and the service is in the U.S. and is geo-blocked.
I've successfully connected to it on my PC when I've got my VPN tunnel activated. I've recently bought a FireTV stick and they have an app to view the service on there. However, again, it is geo-blocked so it won't work.
The problem is that I can't install a VPN on the Fire TV stick directly because my firmware won't let me root it. So, I would like to do it at the router level. With my VPN I also have access to a proxy. So my thought is that I can configure pfSense to use a proxy for ONE IP only.
I don't want to just turn the VPN on for the whole network because there are a lot of e-commerce sites that that have security protocols that block VPN/Proxy purchases. My family is not technically inclined so it needs to be something behind the scenes.
Can someone tell me if this is possible with pfSense and if so how to set it up?
-
I haven't done it but you might try looking into a site-to-site IPSec connection between your pfSense box and your VPN host, with a firewall rule that routes your specific client traffic through the IPSec interface.
https://doc.pfsense.org/index.php/What_is_policy_routing
https://doc.pfsense.org/index.php/VPN_Capability_IPsec
-
I'm afraid I'm not very knowledgeable when it comes to networking… I read those links but I get confused easily.
Could someone tell me how to do this:
1. Setup the IPSec (I use Private Internet Access as my VPN provider)
2. Allow all traffic on the network by default to NOT use the VPN.
3. Setup one IP address rules (192.168.1.66) to use the IPSec VPN.I would appreciate any help I can get please.
-
I'm afraid I'm not very knowledgeable when it comes to networking.
Which begs the question why are you trying to configure an IPsec VPN on a fairly complex routing firewall in the first place? I'm not trying to bust your balls, but this stuff is not for people who are networking beginners. You will find that the people here are very knowledgeable, but they won't do it all for you.
Check out some of these tutorials to get yourself started. Come back if you get stuck or have specific questions.
If that doesn't get you going, then perhaps investing in an incident from pfSense Support might be in order.
You could also try offering a bounty in the Bounty forum and perhaps someone will connect with you and do it for you for a nominal fee.