HowTo: Route part of your LAN via TorGuard or PIA.
-
Policy routing is your friend.
Is there something I'm missing? I have PIA traffic tagged with NO_WAN_EGRESS but I want to say that is somehow messing up the rest of my LAN traffic when I have that "route add" option/checkbox.
I can't even ping out there so I'm guessing it somehow is getting tagged as well (not sure how.)
I think I might have something to test though- The rule on the PIA interface was defined as all for source (which then applies the tag) so I restricted that to my VPN subnet for source. We'll see. Not home so I can't test it.
Thanks mate
-
If you are tagging all traffic with NO_WAN_EGRESS then blocking all traffic with that tag from egressing WAN, then yes, all traffic will be blocked and nothing will work unless it is routed out the VPN.
Set NO_WAN_EGRESS on the rules that policy route traffic you want to go out the VPN out the VPN. Then it will only be set on VPN traffic.
-
If you are tagging all traffic with NO_WAN_EGRESS then blocking all traffic with that tag from egressing WAN, then yes, all traffic will be blocked and nothing will work unless it is routed out the VPN.
Set NO_WAN_EGRESS on the rules that policy route traffic you want to go out the VPN out the VPN. Then it will only be set on VPN traffic.
Think I got it- it was squid. Note to people getting this far- READ THE WHOLE THREAD.
Kinda slipped my mind somehow (I had disabled other things) but that seems to be the big hangup.Thanks OP for a fantastic guide (with pics!) and thanks Derelict for getting me looking in the right direction.
Edit- do my traffic stats jump a lot as well for the LAN? (I have traffic stats tool package installed.) It looks right for packets OUT via PIA but seems the traffic in comes via LAN (which I assume is right.) The traffic stops/starts when I stop the tunnel and restart so I assume this is correct but just double checking.
-
Did a lot of the screenshots disappear when forums migrated to netgate? :(
-
@poisonvodka said in HowTo: Route part of your LAN via TorGuard or PIA.:
Did a lot of the screenshots disappear when forums migrated to netgate? :(
Yep.
But never mind, screenshots from 2 years back aren't very useful anyway - as is probably most info in this thread.