PBR: bypass domain with killswitch


So I'm trying to split tunnel some domains so it doesn't use my wireguard.

under normal circumstances this should work when the traditional firewall zone config forwarded to both zones wan and wgclient, however I decided to change the firewall zone forwards a little and removed wan entirely so it works like a better killswitch.

some screenshots to highlight what I mean (the last 3 rules):

and firewall zones:

basicly what I want is for the network pcnet (firewall zone pcnet and network: to preroute to wan for those domains, however I keep getting connection refused messages, I was thinking to put a forward after it as shown in the screenshot but that seems not to work, in PBR I forgot to add src ip for pcnet but im aware of that :stuck_out_tongue:

help is much appreciated!

thanks :smiley:

I figured it out !

the reason why my split tunnel was not working was indeed because it wasn't forwarded from zone pcnet to zone wan because pcnet only was allowed to forward to zone wgclient.

the solution was very easy:

I had to type ip rule to see the firewall marks for table pbr_wan, then the solution was very easily create a traffic rule like this where the firewall mark is the one for pbr_wan:

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.