Exclude websites from vpn on Flint 2 480-op24

As per my post here:

I cannot exclude a website without the entire network losing the WG VPN.
As no responses from staff there, I have reposted here.
Please advise.

Hello,

Is blocking other websites the same result?

What are the three websites you added to the VPN exclusion list? Are there any special features about them?

Could you send them to us? We'll try to set up an environment to reproduce the issue.

Hi.
Any website excluded (via Specified Domain / IP List) results in the vpn disappearing eventually.
Sometimes immediately, sometimes a few days later.
Note that I have 2 specified devices also excluded at all times.
Three sites:
www.gumtree.com.au
forums.whirlpool.net.au

I currently have this configuration: all client accesses to two specific domain names go through the VPN tunnel.

Testing revealed that the VPN tunnel isn't used when accessing the website, but rather the WAN IP.

This seems to replicate your issue; I need to re-verify the VPN policy logic here.

Can I see a screenshot of your configuration? please.

You need to exclude at least one device as well, to match what I need.
Here are two setups:

  1. Exclude websites - this seems to do NOTHING
  2. Specify websites - this brings down the VPN for ALL devices

Hi,

I have reproduced this issue, but the specified website inaccessible, as probably the VPN DNS resolve does not work, if the requested address is IP, it can be reachable in VPN.

The issue has been submitted to R&D to check and repair.
Thank you for your feedback!

2 Likes

Thank you for looking into this!
I do think that it's important to have an excluded DEVICE at the same time as excluding a website.
There may be some interaction there.
I can't test here at present as I would have a family fight - the Smart TV needs to be excluded from VPN for streaming services to work.

Sorry for the inconvenience.

Yes, this is an important feature of 4.8.x VPN, which is a link in the strategy.

Thank you! We are able to reproduce the issue in router, so without you continuing to test it.

When R&D release a new version which it improved this issue, I will update to you.

1 Like

Hi @covenant

Maybe we need to help, could you please provide remote access router through GoodCloud, we would like to check the device about this VPN issue.

Our environment has not been reproduced this in recent days, resulting in the inability to further check by R&D team.
Maybe when I reproduced it, it happened that the VPN tunnel connection was unstable at that time, and similar phenomena occurred, which led to my misjudgment of it reproduces.

Hi Bruce.
I'd rather not allow remote access if that's ok.
I will workaround the issue for now, although I think it happens if both a device AND a website is excluded.
It seems to also happen in my old router running openwrt 24.10.1 so it may be an underlying error with PBR that may now be ok with 24.10.2. and later PBR component.

Hi,

We did not reproduce this issue in our router, and tested Exclude and not in v4.8.1 (snapshot) of MT6000:

DNS resolution is normal, routing is normal, ie. VPN rules are normal.

If possible, please share us your router with us through GoodCloud to check.