VPN based on VLAN doesn't apply? 4.9

Hey guys,

I’m trying to setup VPN based on an VLAN for a specific port on my Flint 2 running firmware 4.9… somehow the vpn policy doesn’t apply. Yeah sure I’ve set specified connection type > vlan5 traffic from vlan5.

Here is what I did:

  1. Network > Interfaces > Device Tab
  2. br-lan configure
  3. Enabled VLAN filtering, set 4 ports to VLAN 1 + untagged + primary VLAN ID
  4. Set port 5 to VLAN 5 + untagged + primary VLAN ID

So basically I’ve made two different vlans, I want to use vlan 5 for wired guest clients and later, I want to use my AX3000 as an access point for my IoT devices on vlan5 which then should be also routed through vpn. Any idea how to achieve this the smoothes way?

5. Network > Interfaces > edit br-lan > set up br-lan.1 as it’s device
6. Created a new device named vlan5 where I’ve setup br-lan.5 as it’s device
7. Created a firewall zone and activated dhcp and let dhcp on standard configuration
8. Network > Firewall
9.
I’ve tried setting
vlan5 forwarding to WAN accept accept reject
vlan5 forwarding to WAN / wgclient accept accept reject
Masquerading off

Nothing works despite dnsleaktest returns vpn ip when vpn is activated (killswitch activated)
What am I doing wrong here? Do you need any kind of configuration to help me?

I also don’t want vlan5 to be able to reach the router/luci, preferably I want to use adguard but not for vlan5. I want vlan5 to be completely separated from the other ports/standard vlan

I’ve also noticed all clients shows as offline in glinet gui, the test device is getting the correct ip subnet and when I’m activating VPN for ALL devices in gui, all devices are connected to VPN BUT NOT VLAN 5 lol

Hi,

Thank you for providing the detailed configuration information.

You can refer to the following guide for creating and configuring VLAN interfaces on Flint 2:

After the VLAN interface is created successfully, it can be selected under VPN Policy → Specified Connection Types in firmware v4.9.

The second tutorial “How to have a custom interface populate in VPN ‘client-sources” only covers setting up LAN2 as a custom interface, but not setting up VLAN2 right?

As said, the option “specify connection type >vlan5” is activated as a custom rule within the vpn dashboard, but it doesn’t route properly…. when I’m forwarding VLAN5 to the correct wgclient, there is just no internet access even the wg config is activated/connected in the dashboard