Project

General

Profile

Actions

Regression #16048

closed

Checking the "Force all traffic thru VPN" within OpenVPN wizard or server configuration does(may?) not add outgoing NAT rule.

Added by Stephen Trotter 2 months ago. Updated 2 months ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
OpenVPN
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default
Affected Plus Version:
24.11
Affected Architecture:
SG-1100

Description

I was attempting to set up an OpenVPN tunnel so I could connect my phone thru my home network.
The desired behavior was to have ALL traffic through the VPN.

I added the server a-la numerous guides and also following documentation.
When complete, I was able to connect and was able to access local resources (on the home network) but unable to route to the Internet.

Eventually I added an Outgoing NAT rule which solved the issue.

I'm unsure if the feature used to, or should, add that outgoing NAT rule automatically.
I had my outgoing NAT set to Manual, so perhaps that was why it wasn't created for me.

But, if that box is checked, I believe it should add the outgoing NAT rule, or there should be an option for it if the feature is selected in the wizard at least (like there is already the options to create the WAN rule and the pass rule in the OpenVPN table).

Actions #1

Updated by Stephen Trotter 2 months ago

I just wanted to add the reasoning that I believe it may be a regression.

It's because of the numerous guides (and the documentation) which say that all you need to do is check the box to force all traffic through the tunnel.

Actions #2

Updated by Jim Pingle 2 months ago

  • Status changed from New to Rejected

Manual NAT rules will never be added automatically unless you're switching from Auto or Hybrid over to Manual. This is no exception. To do otherwise would be unexpected since Manual mode is supposed to be fully manual once set.

If you want automatic NAT, you should be on Automatic or Hybrid mode, not manual.

Actions #3

Updated by Stephen Trotter 2 months ago

Okay, gotcha! I wasn't sure if that was the issue. Thanks for the quick reply!

Actions

Also available in: Atom PDF