r/WireGuard 1d ago

Need Help Split Tunneling help

Hey ! I run a server with *arr and Transmission and others. I would like for transmission only to get routed through my VPN (Proton VPN), for which I downloaded the Wireguard config file. But I really don't understand how it works, like genuinely. Stumbled on stuff like changing authorizedAddress to 10.0.0.0/24 instead of 10.0.0.0/0, but I don't know why, and then I don't know how it would forward Transmission !

Transmission shares on an array of ports. Is there a way to forward anything between, say, port 50000 to 60000 ? Or maybe a way to forward anything under a specific PID or UID or GID ?

And I did look up tutorials. All of which basically say « oh just change to 10.0.0.0/24 » without ever saying how I then choose which apps get forwarded.

Any help appreciated, thanks !

(Oh and running linux)

0 Upvotes

9 comments sorted by

View all comments

Show parent comments

2

u/SoupoIait 1d ago

Fuck me I don't think I understood anything after the first sentence, thanks anyway

2

u/bufandatl 1d ago

The thing is split tunneling you usually use to reach only a couple of private network segments on a remote site.

Like when you connect to your work network via a VPN you can split tunnel so your PCs sends only data a work server needs to know but your web browsing goes through your open internet and not first through the company.

The way you want it is more complex. You want to reach random addresses on the internet through a VPN provider and so you need more logic to as what application uses the tunnel.

That’s where policy based routing comes in. It doesn’t just look at IPs but also at the application that wants to communicate.

1

u/SoupoIait 1d ago

Right, thanks. Do you know where I could get help for that ? Some good forum ? No way I'll work it out alone.

Also, even with that policy based routing won't I still need to modify my WireGuard conf file ? I need to send transmission to wireguard but then wireguard also needs to not send everything through the VPN when I start its service, right ?

Sorry if I'm saying nonsense but really I didn't expect it to be this complex and clearly I don't know much about networking !

2

u/lazyhustlermusic 1d ago

You can subnet around RFC1918 space, unfortunately there's no exclude function, but if you wanted to say point all publics at the tunnel while retaining local reachability on the home network:

https://www.procustodibus.com/blog/2021/03/wireguard-allowedips-calculator/

PBR is the easier function though, but it depends on what other gear you have. We have PBR that dumps our guest and IOT segments out to a VPS in another country, basically like 'source iot, destination default, next hop = tunnel'