Location being disovered on GL -BE3600 Slate

Hi, I’m in Medellin and a client of mine discovered I was out of the country and I’m not sure how. I’m using my travel router via wireguard with the kill switch on to block traffic outside of the vpn. My home slate is in Charlotte and when I do a dnsleaktest its showing no leaks and checking whatsmyip its coming up with my slate wireguard server ip address at home which is normal. The location is also showing up in Charlotte although I’m in Medellin, so that checks out also. What am I missing here that they picked up on my location? I’m hardwired into the airbnb router and I don’t have any additional devices connected to the router. Highly confused how this was possible, but looking for some assistance on how it happened. Also, I’m using the clients laptop and I go through their vpn using global protect their software.

My guess here what could have been happening is this:

Your browser has, or a program leveraging a background web app, leaks webrtc.

webrtc is quite being used for video calls, but because it uses stun servers to map your network it can also bypass vpn.

The solution would be best to find a way to disable webrtc, you can try browserleaks to test it.

Note that in Windows, if you use a different default browser a app still use edge here, so also make sure it is off there aswell or avoid these services at all.

^ note: this is only true if the vpn was not setup on the router, it is not clear to me what you mean by:

It is also possible if the vpn run on the laptop, that they could have access to all your lan ip, even a simple ipv6 address could be leaked like that, and this is often also a public ip directly, that is also how vpn virtual tunnel ip can be discovered.

I don’t believe the browser is the issue. As I mentioned this is a client issued laptop and I don’t use any apps on it outside of client bases apps. Not even google for anything. Also, in order to get into their systems, they have an app called Global protect that you sign into that sends a microsoft authenticator code to your phone that you have to verify that gets you into their apps through their vpn. I don’t have my vpn on because I contact through by glinet router via wireguard that runs the traffic back to Charlotte through my isp ATT. Something is happening on the router because this hasn’t happened before.

Any response from the GLinet people? I’d really like to find out why this is happening all of a sudden