Different VPN per site? Flint AX & WireGuard

I can attest stangri’s PBR for LuCI is a rather impressive piece of software.

Yeah, @xize11 is right on point; it’s not going to be an easy time using GL firmware. luci-app-pbr will certainly conflict & for best results it’s best to have full nft tables for the firewall vs iptables… nft is now the default as of OpenWrt 23.05 but the Flint is still using 21.02 in firmware 4.4.6-release1. You’d also need dnsmasq-full (v2.39+) & not just stock/regular dnsmasq.

If you can afford the hit to the wallet, I’d pick up another Flint or a Slate AX & flash it with @solidus1983 's ‘pure’ OpenWrt firmware build for it. While there might be a hit to the device’s overall performance as it doesn’t have GL’s optimizations via the proprietary SDK, you’ll have full access to all things OpenWrt. You could then put this pure OpenWrt behind/downstream of your GL Flint to handle whatever device clients you want to use PBR.

Of course you can always just pick up a compatible OpenWrt router on the used market for experimentation… but it can be done & close to a case of ‘easier done than said.’

2 Likes