1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Route Certain Ports Off VPN

Discussion in 'Tomato Firmware' started by outernational, Mar 28, 2017.

  1. outernational

    outernational Network Newbie Member

    I am trying to get better quality for VoIP from clients that are inside the VPN (which has greater latency and reduced bandwidth), by routing the VoIP services outside the VPN.

    Via a PBR policy, only clients inside 192.168.1.128/25 are routed thru OpenVPN.

    I would like to exclude all VoIP from being routed thru the VPN. I've carefully setup all VoIP (Viber, Skype, and WhatsApp - Google Voice is in the DMZ) as a QoS class.

    The easiest way would be to route this QoS class off the VPN. Is this possible (Q1)? I am guessing it is not possible (that would be too easy).

    It has been pointed out many times (usually when people ask about Netflix) it is impractical to exclude using IP sets (WhatsApp alone has over 240 CIDRs it can use).

    So how to route certain destination ports off the VPN (Q2) on Tomato 138 K26ARM USB VPN-64K?
     
    Last edited: Apr 3, 2017
  2. cloneman

    cloneman Networkin' Nut Member

    minor note: you'll want to increase the minimum for your VPN. since your VPN is much slower than your Wan, there's no reason to constrain it any further with QoS. if some class gets caught in VoIP (eg. videoconf) VPN could potentially be limited to 5% of 10mbps in that setup

    qos classifier uses iptables to mark traffic for sorting. perhaps you can also use similar iptables rules to specify an alternate Wan destination
     
    outernational likes this.
  3. outernational

    outernational Network Newbie Member

    note taken, Cloneman. Makes sense. I will put the min at 80%.
     
  4. outernational

    outernational Network Newbie Member

    iptables rules to specify an alternate Wan destination: that is a possibility worth exploring.
     
  5. outernational

    outernational Network Newbie Member

  6. Muttontop

    Muttontop New Member Member

    Hi
    Sorry I can't add any more to this topic but as a newbie I need to have made two posts before I can start a thread to ask a question!!!! This being my first Post.
     
  7. outernational

    outernational Network Newbie Member

    how to route dport 995 off the VPN (Q2) on Tomato 138 K26ARM USB VPN-64K? PBR for the VPN is set to 192.168.1.128/25
     

Share This Page