I have a work PC that struggles to run its own VPN through the VPN on my router. I tried to set up an interface and a firewall zone for it, but can get only one of the interfaces working at any given time.
My set up (as it was):
interface br-lan (static IP with DHCP over ethernet ports, 2.4 and 5 GHz wlan), zone lan
interface wan (DHCP4), zone wan
interface tun0 (Unmanaged, OpenVPN), zone vpn
firewall setup was trivial:
zone lan accept-accept-accept, forward to vpn
zone wan reject-accept-reject, masq
zone vpn reject-accept-reject, masq
What I added:
separate wlan gwlan0
interface br-guestlan (static IP with DHCP over gwlan0), zone guestlan
firewall:
zone guestlan accept-accept-reject, forward to wan
After this only one of the interfaces (lan and guestlan) has internet access. Sometimes OpenWRT adds wan's gateway and lan and guestlan gateway (and then guestlan works), sometimes it doesn't and my OpenVPN actually manages to connect. Adding wan's gateway IP as guestlan's gateway IP manually doesn't help.
Am I on the right track at all, or am I using the wrong tools?