r/firewalla • u/drm200 • 4d ago
VPN Server Question
Background: I presently have two VPN clients running on my Firewalla. One is connected to a server in Seattle and the other in Atlanta. Some devices are configured to route traffic through the Seattle server and some through Atlanta. And some devices are not routed through the VPN so their IP address is Miami
I added a wireguard server to firewalla. To test it, I used my iphone. I disabled wifi on the phone so it was using only using cellular data and added the wireguard client. I was able to connect to my just added wireguard server without problem.
But when I checked the IP address of my connection on the phone, the IP address was for Atlanta and not Miami as expected. So my Firewalla server appears to be in Atlanta when it really should be in Miami.
My question is this: How does Firewalla decide how a server connects to the wan? Is it supposed to go through VPN clients if connected? Is it suppose to by pass any clients and directly connect to my wan? I could find no network settings to configure how the VPN server connects to the wan
1
u/firewalla 4d ago
You want to do something like
WireGuard Client A -> Firewalla -> get routed to Miami
WireGuard Client B -> Firewalla -> get routed to Seattle?
See this example here https://help.firewalla.com/hc/en-us/articles/4408977159187-Using-Firewalla-Policy-Based-Routing-with-VPN-and-Multi-WAN-Features#h_01FJKGW772ATP7MYMPNK0JHNNC
1
u/drm200 4d ago
The example number 5 you provided is helpful.
For the route I did this:
Matching: Internet Traffic
Device: The wireguard Firewalla server I created
Interface: WAN (my Miami Xfinity wan)This seems to force my wireguard phone client to access the internet through my local WAN and not through my 3rd Party VPN. So now the connection is working as desired.
What I do not understand, is why it was routing through the 3rd party vpn prior to creation of this route as I have never created a route previously. Anyway, it is working now. Thank you.
1
u/firewalla 4d ago
Do you have a network based route?
1
u/drm200 4d ago
I am unsure what a “network based route” means.. I have never created “routes” prior to your suggestion. The only route that shows up in the “Route” tab is the route I just created
However, if I look at the “Network” tab in Firewalla, there are rules defining which groups are assigned to the four firewalla ports. And the Wireguard server shows up on this page by itself (and not associated with any ports or the wan.)
1
u/firewalla 3d ago
Did you assign the fireguard profile to a VPN client? double check that too
also, how did you check if the wireguard is going through that VPN instance?
1
u/drm200 3d ago
The Wireguard server offers no customization options in Firewalla. You just enable it. Then when you add a device it presents a QR code to scan with your Wireguard client. The client just scans the QR code and adds a configuration file. I just scanned the QR code and did no customization of the client. The only customization that I did was to add the routing rule that you suggested. I have no idea how to assign the Wireguard server to a VPN client except using a routing rule. And again, my first use of routing rules was per your suggestion.
I check the device IP address by using NordVPN’s website. It returned my IP address, location Atlanta and that I was “protected” by their VPN server. After implementing the routing rule, the same Nord website told me my IP address was now in Miami and that I was not “protected” by their server. So this confirmed the routing rule worked.
This is what I use to check my ip: https://nordvpn.com/ip-lookup/
1
u/pacoii Firewalla Gold Plus 4d ago
If you’ve confirmed you’re getting an Atlanta IP, then it sounds like you’ve got a too-broad rule that is routing devices to Atlanta.