Flint-2: VPN and Policy Routing

Hi there,

I’m using a Flint 2 (GL-MT6000) on firmware 4.9.0 beta and really like the new VPN Dashboard in Policy Mode.

My use case is:

  • Some specific devices in the LAN should go through the VPN with All Targets (full tunnel).

  • All other devices should only route specific domains + IP ranges through the same VPN, while the rest of their traffic goes directly to the internet.

Currently, it looks like one Tunnel = only one rule (either “Specified Devices → All Targets” or “All Clients → Specified Domain/IP List”).
To achieve the above I have to create two separate Tunnels using the same VPN profile.

My questions:

  1. Is it possible (or planned) to attach multiple rules/policies to a single Tunnel? For example, inside one Tunnel have several “From → To” conditions that are evaluated in order.

  2. If not, what is the recommended way to achieve the scenario above while keeping only one real VPN connection (one WireGuard interface)?

Hi

Please refer to our responses below:

  1. We currently do not support attaching multiple rules/policies to a single tunnel. You can achieve this by creating multiple tunnels.
  2. When multiple tunnels use the same WireGuard configuration file, only one WireGuard interface will be created, as shown below: