Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Optional tunnel all for mobile clients

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Trel
      last edited by

      Is there any way I can have it that mobile clients by default do not tunnel all, but the client can enable it if necessary?
      (PFSense is the server, various machines (Windows, Linux, Android) are the clients)

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        I'd say it depends on the client. Attached is a Viscosity for Mac screenshot.

        An alternative would be two OpenVPN servers, one that pushes the default gateway and DNS servers and one that does split tunneling. The client could connect to the one with the desired behavior.

        Viscosity-Config.png_thumb
        Viscosity-Config.png

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • T
          Trel
          last edited by

          @Derelict:

          I'd say it depends on the client. Attached is a Viscosity for Mac screenshot.

          An alternative would be two OpenVPN servers, one that pushes the default gateway and DNS servers and one that does split tunneling. The client could connect to the one with the desired behavior.

          Two servers is how I currently do it.

          Other than Viscosity, do you happen to know of any good Windows (mostly this) + Linux (but this too) OpenVPN clients w/ GUI if possible?  (I know that's not technically what I asked originally)

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Hmm. Last thing I want is my users getting in there and clicky-clicky around.

            What you currently use doesn't do it?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • T
              Trel
              last edited by

              @Derelict:

              Hmm. Last thing I want is my users getting in there and clicky-clicky around.

              What you currently use doesn't do it?

              This is what I currently use (on Windows at least): https://community.openvpn.net/openvpn/wiki/OpenVPN-GUI

              Not exactly the best option, especially when it comes to the end user.  I'd much rather them have a checkbox than attempting to edit a config file.

              1 Reply Last reply Reply Quote 0
              • S
                Snailkhan
                last edited by

                @Trel:

                Is there any way I can have it that mobile clients by default do not tunnel all, but the client can enable it if necessary?
                (PFSense is the server, various machines (Windows, Linux, Android) are the clients)

                Are you talking of split tunneling?

                I tested with openvpn in pfsense  with Android and it was working.

                In openvpn android client you can check uncheck this options..

                Not sure if Linux Mac or Windows.

                I will test it those gadgets and let you know.

                I did a temporary setup where I put pfsense behind cisco 1841 router and applied qos to restrict bandwidth. When I was connected via vpn to it I was getting that pathetic speed in browsing and site to site data transfer. And what is my ip would show that all my traffic is routed via my open vpn server.

                However when I enabled split tunneling in client on Android browsing speed became normal.  But site to site was still slow.

                And what is my ip would show me Wan address of the local network.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.