Policy-based routing?

Currently reading
Policy-based routing?

2,279
956
NAS
DS220+ : DS1019+ : DS920+ : DS118 : APC Back UPS ES 700 — Mac/iOS user
Hi,

A friend asked me if any of Synology’s routers support policy-based routing. I didn’t know (never used Synology routers) and we tried to quickly look for that info to no avail. An example of what he wants to do is to route certain domains (from single or multiple clients on the LAN or connected to the router over the router‘s VPN server) over a VPN connection established by the router (to a VPN provider like Proton, Mullvad or a VPN server). Another is to route traffic to certain countries to go over another VPN connection.

How many VPN connections can the router support (as in client mode to VPN providers or servers)?

If this is supported, how easy is it to implement? Is it on the SRM interface or must he use the CLI?


Thank you for any information.
 
If this is supported, how easy is it to implement? Is it on the SRM interface or must he use the CLI?
1674718134665.png
 
Upvote 0
As far as I’m aware this routing adds source IP to the usual destination IP-only. But it doesn’t included packet inspection to determine the payload’s type or destination FQDN.

You can do FQDN-like routing for fairly static destination IPs, but this will have to be manual. If you can establish the set of IPs, or subnets, being used then it’s fairly simple. But then I guess you already know this.

You could run a forward proxy server on the LAN with PAC file that specifies the destinations that use the proxy and default everything else to go direct. Then route the proxy as source IP via the alternate WAN path.
 
Upvote 0
prefect! Thanks for this thread - I was actually looking for this for quite a while:
Now I have my own secondary WLAN, routing all traffic via my VPN. No need for the client to set up VPN. 🥳

  1. I set up a new WLAN (SSID '… VPN') using its own subnet (WiFi Connect)
  2. I set up a VPN in Network-Center > Internet > Connections > VPN
  3. I set up Static Routes in Network-Center > Internet > Smart Wan > Policy Route to route traffic from that sub-net thru the VPN.
The only tricky part was, not to route the Gateway IP (192.168.x.1) thru VPN.

Now I just have to connect to the WLAN "… VPN" on any device to route thru my VPN connection.

Finally, I am able to use my AppleTV and other clients using my "location flexible" VPN 😁

Thanks!
 
Upvote 0

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top