<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Opnsense on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/opnsense/</link>
    <description>Recent content in Opnsense on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/opnsense/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Routing to Tailscale clients from a local network with OPNSense</title>
      <link>https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/</link>
      <pubDate>Sat, 15 Aug 2026 16:45:12 -0400</pubDate>
      <guid>https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/</guid>
      <description>&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;&#xA;&lt;p&gt;Effectively, what we&amp;rsquo;re trying to accomplish here today is the opposite of a Tailscale &lt;a href=&#34;https://tailscale.com/docs/features/subnet-routers&#34;&gt;Subnet Router&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;As in, allowing clients on our local network to talk to devices via their &lt;a href=&#34;https://tailscale.com/docs/concepts/tailscale-ip-addresses&#34;&gt;Tailscale subnet IP addresses&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;When I started looking into how to do this, I could not find a complete guide on the topic.&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;ll do my best to do this start to finish so that anyone else can follow along with me.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;You already have an OPNSense gateway setup and enabled as a Subnet Router on your Tailnet.&lt;/li&gt;&#xA;&lt;li&gt;You&amp;rsquo;ll also need to have approved the subnets that you told the Subnet Router to advertise in your admin console.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h2 id=&#34;recommendations&#34;&gt;Recommendations&lt;/h2&gt;&#xA;&lt;p&gt;Create an alias for the Tailscale subnet range so you can avoid typing it in 10x times.&lt;/p&gt;&#xA;&lt;p&gt;Firewall &amp;gt; Aliases&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;Showing alias for tailscale subnet&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-alias.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;explanation&#34;&gt;Explanation&lt;/h2&gt;&#xA;&lt;p&gt;Tailscale Subnet Routers by default use SNAT (Source NAT).&lt;/p&gt;&#xA;&lt;p&gt;This means that packets sent from your Tailscale devices &lt;em&gt;to&lt;/em&gt; the Subnet Router will go through Network Address Translation on their way to the local subnets you&amp;rsquo;ve advertised.&lt;/p&gt;&#xA;&lt;p&gt;So, any devices &lt;em&gt;inside&lt;/em&gt; your LAN by default will only ever see the IP address of your OPNSense gateway - they will not see the IP addresses of the individual Tailscale clients. This is the first thing that we will need to disable.&lt;/p&gt;&#xA;&lt;p&gt;Once we have this disabled, we&amp;rsquo;ll need to configure both a static route as well as firewall rules to allow the traffic to pass.&lt;/p&gt;&#xA;&lt;h2 id=&#34;step-by-step&#34;&gt;Step by step&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Log into your OPNSense router and navigate to VPN &amp;gt; Tailscale &amp;gt; Settings. You&amp;rsquo;ll need to toggle on &amp;ldquo;Advanced Mode&amp;rdquo;. Check the box for &amp;ldquo;Disable SNAT&amp;rdquo;.&#xA;&lt;img alt=&#34;Image showing how to disable SNAT in Tailscale&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-disable-snat.png&#34;&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Now, what we need to do is create a static route - but before we can do that, we need to take care of some other items:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Add the Tailscale interface by going to Interfaces &amp;gt; Assignments. Click on the + button and add the Tailscale interface from the dropdown. Don&amp;rsquo;t forget to enable the interface - by default it will be added in a disabled state.&#xA;&lt;img alt=&#34;Tailscale interface in OPNSense&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-interface.png&#34;&gt;&#xA;&lt;img alt=&#34;Tailscale interface configuration&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-interface-2.png&#34;&gt;&lt;/li&gt;&#xA;&lt;li&gt;Create a new gateway - System &amp;gt; Gateways &amp;gt; Configuration. The interface should be &amp;ldquo;Tailscale&amp;rdquo;. Gateway name is technically arbitrary, but for the sake of simplicity I&amp;rsquo;ve also called it &amp;ldquo;Tailscale&amp;rdquo;. Make sure you disable gateway monitoring.&#xA;&lt;img alt=&#34;Tailscale Gateway setup&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-gateway.png&#34;&gt;&lt;/li&gt;&#xA;&lt;li&gt;Now that we&amp;rsquo;ve done this, we can finally define our static route (System &amp;gt; Routes &amp;gt; Configuration). The Tailscale subnet is 100.64.0.0/10:&#xA;&lt;img alt=&#34;Tailscale static route configuration page&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-route.png&#34;&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Now that we have the routing taken care of, we need to create some firewall rules to allow the traffic to pass. You&amp;rsquo;ll need to create at minimum 2 rules on the OPNSense side (Firewall &amp;gt; Rules):&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;On your LAN interface, define a rule that allows communication from your LAN to your Tailnet. For example -&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Interface: LAN (Or whatever yours is called)&#xA;Action: Pass&#xA;Source: LAN network&#xA;Destination: 100.64.0.0/10&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;&#xA;&lt;li&gt;On your Tailscale interface, define the inverse:&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Interface: Tailscale&#xA;Action: Pass&#xA;Source: 100.64.0.0/10&#xA;Destination: LAN network&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Rule 1 may not be needed if you have the default &amp;ldquo;Allow All&amp;rdquo; rule in your configuration on the LAN interface. I do not, so I needed to allow that traffic.&lt;/p&gt;&#xA;&lt;p&gt;Feel free to restrict this traffic however you would like. Personally, I only allow through a few kinds of traffic - DNS, HTTP/HTTPS, and ICMP echo-request / echo-reply.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;You&amp;rsquo;ll also need to go into your &lt;a href=&#34;https://console.tailscale.com/admin/acls/visual/general-access-rules&#34;&gt;Tailscale ACL controls&lt;/a&gt; and allow access there from your local subnets.&#xA;&lt;img alt=&#34;Tailscale ACL screenshot&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-acl.png&#34;&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Any device that you wish to reach via this connection needs to have the &lt;code&gt;--accept-routes&lt;/code&gt; option enabled when you run &lt;code&gt;tailscale up&lt;/code&gt;. The device you&amp;rsquo;re trying to access needs to have a route to get &lt;em&gt;back&lt;/em&gt; to your LAN subnet, after all.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;--accept-routes&lt;/code&gt; is enabled by default on MacOS and Windows, but disabled by default on Linux. Once enabled, the device should be reachable from any device on your LAN.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;You may also want to configure MSS clamping to avoid unnecessary IP fragmentation. Under Firewall &amp;gt; Settings &amp;gt; Normalization, click the + to add a new rule:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Interface: Select your assigned Tailscale interface.&#xA;Direction: Any&#xA;Max MSS: 1240 (for standard Tailscale 1280 MTU) or 1380 (if your Tailnet uses 1420 MTU).&#xA;Description: Clamp MSS for Tailscale traffic.&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;I highly recommend thinking carefully about your firewall rules and Tailscale ACLs, and what you allow to connect to what.&lt;/p&gt;&#xA;&lt;p&gt;Now that I&amp;rsquo;ve gotten this working I&amp;rsquo;ll be spending some time narrowing my LAN to Tailnet access ACL down to specific tags. But that&amp;rsquo;s a whole other post.&lt;/p&gt;&#xA;&lt;h2 id=&#34;exit-node&#34;&gt;Exit Node&lt;/h2&gt;&#xA;&lt;p&gt;If, like me, you are also using your home OPNSense gateway as a Tailscale &lt;a href=&#34;https://tailscale.com/docs/features/exit-nodes&#34;&gt;Exit Node&lt;/a&gt;, you&amp;rsquo;ll quickly realize that this process broke it.&lt;/p&gt;&#xA;&lt;p&gt;The fix is simple, we need to add an Outbound NAT rule to replace the missing SNAT on the Tailscale service.&lt;/p&gt;&#xA;&lt;p&gt;Go to Firewall &amp;gt; NAT &amp;gt; Outbound.&lt;/p&gt;&#xA;&lt;p&gt;Your Outbound NAT mode must be set to &amp;ldquo;Hybrid&amp;rdquo; or &amp;ldquo;Manual&amp;rdquo;. If you don&amp;rsquo;t know what this means, set it to &amp;ldquo;Hybrid&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;Configure a rule that looks like this:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Interface: WAN&#xA;Source address: 100.64.0.0/10&#xA;Destination address: any&#xA;Translation target: Interface address&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;img alt=&#34;Example of outbound NAT rule&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/opnsense-lan-to-tailscale-connectivity/images/tailscale-nat.png&#34;&gt;.&lt;/p&gt;&#xA;</description>
    </item>
    <item>
      <title>Setting up OpnSense as an AirVPN client</title>
      <link>https://blog.ssb-tech.net/posts/airvpn-on-opnsense/</link>
      <pubDate>Tue, 03 Dec 2024 22:41:53 -0500</pubDate>
      <guid>https://blog.ssb-tech.net/posts/airvpn-on-opnsense/</guid>
      <description>&lt;p&gt;I recently set up my OpnSense firewall at home with a connection to AirVPN using Wireguard.&lt;/p&gt;&#xA;&lt;p&gt;It was a bit more complicated than when I did it for Mullvad last year, so I figured I&amp;rsquo;d document it here for anyone who finds this useful.&lt;/p&gt;&#xA;&lt;h2 id=&#34;1-device-creation&#34;&gt;1. Device Creation&lt;/h2&gt;&#xA;&lt;p&gt;Log into your AirVPN account and navigate to the client area. Click on&#xA;Manage Devices. You can either edit the existing &amp;ldquo;default&amp;rdquo; device or&#xA;create a new one. Either way, I recommend editing the name of the device&#xA;so that you know what it is, 6 months down the line. I called mine&#xA;&amp;ldquo;Opnsense&amp;rdquo;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;While you&amp;rsquo;re here, I recommend opening up a Notepad or equivalent and&#xA;copying and pasting the public key that&amp;rsquo;s on this page. We&amp;rsquo;ll need it later.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;AirVPN devices page&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/airvpn-on-opnsense/images/airvpn-devices.png&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;2-generate-wireguard-configuration-file&#34;&gt;2. Generate Wireguard configuration file&lt;/h2&gt;&#xA;&lt;p&gt;Next, head back to the client area and head into the Config Generator.&lt;/p&gt;&#xA;&lt;p&gt;For OS, you&amp;rsquo;ll want to choose &amp;ldquo;Router&amp;rdquo;. You&amp;rsquo;ll also want to decide which&#xA;device (if you have more than one) that this configuration will apply to.&lt;/p&gt;&#xA;&lt;p&gt;Pick the &amp;ldquo;Wireguard&amp;rdquo; protocol.&lt;/p&gt;&#xA;&lt;p&gt;Pick a server as well - I picked Switzerland.&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;re done, click the Generate button at the bottom of the page.&#xA;This will download a Wireguard configuration file - save this, we&amp;rsquo;ll need&#xA;it in a moment.&lt;/p&gt;&#xA;&lt;h2 id=&#34;3-create-wireguard-tunnel-in-opnsense&#34;&gt;3. Create Wireguard tunnel in Opnsense.&lt;/h2&gt;&#xA;&lt;p&gt;Next, we&amp;rsquo;ll be heading into Opnsense. Log in and navigate to the VPN&#xA;section. Under Wireguard, create a peer.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Name: AirVPN &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Public Key: you can get this from the wireguard configuration file you downloaded in step 2.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Pre-Shared Key: you can get this from the wireguard configuration file you&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;downloaded in Step 2. &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Allowed IPs: 0.0.0.0/0 &#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Endpoint Address: Get this from the config file as well.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Endpoint port: Get this from the config file as well. It&amp;#39;s usually 1637.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Keepalive Interval: You can either set this to 15 or leave it blank.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Save, and next we&amp;rsquo;ll head over to Instances. Configure a new instance with the following options:&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Make sure you enable advanced features.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Name: AirVPNLocal&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Public Key: Here you&amp;#39;ll want to put the public key we got in step 1. This is the public key of OPNSENSE.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Private Key: Grab this from the config file. It will be under the Interface section.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Tunnel address: Set this to the /32 address that was in the config file. It will be something in the 10.128.0.0/10 range.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Peer: Select the AirVPN peer we created earlier.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;MTU: 1320&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Disable Routes: Checked &#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Make sure you have Disable Routes checked, it&amp;rsquo;s important.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hit Save. Don&amp;rsquo;t forget to check the box to enable Wireguard, and hit apply at the bottom of the page.&lt;/p&gt;&#xA;&lt;p&gt;Once done, head over to the &amp;ldquo;Status&amp;rdquo; page - the tunnel should show a status of &amp;ldquo;Up&amp;rdquo; now, but we&amp;rsquo;ve still got some work to do before we can use it.&lt;/p&gt;&#xA;&lt;h2 id=&#34;4-create-an-interface&#34;&gt;4. Create an interface.&lt;/h2&gt;&#xA;&lt;p&gt;Head over to Interfaces &amp;gt; Assignments.&lt;/p&gt;&#xA;&lt;p&gt;Under &amp;ldquo;Assign a new interface&amp;rdquo;, pick the Wireguard device we just created. If it&amp;rsquo;s your first one, it&amp;rsquo;ll be &lt;code&gt;wg0&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Click on the interface, Enable it. I also recommend giving it a descriptive name. Mine is called &amp;ldquo;airvpn_wg&amp;rdquo;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;5-create-a-gateway&#34;&gt;5. Create a gateway.&lt;/h2&gt;&#xA;&lt;p&gt;Next we have to create a gateway for AirVPN clients to use.&lt;/p&gt;&#xA;&lt;p&gt;Head over to System &amp;gt; Gateways &amp;gt; Configuration.&lt;/p&gt;&#xA;&lt;p&gt;Create a new gateway and give it a descriptive name. I called mine AIRVPN_GW.&lt;/p&gt;&#xA;&lt;p&gt;Here are the other settings you&amp;rsquo;ll need to configure on this gateway.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Address family: IPv4&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;IP Address: 10.128.0.1&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Far Gateway: checked&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Disable Gateway Monitoring: checked.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Click Save, and then Apply.&lt;/p&gt;&#xA;&lt;h2 id=&#34;6-create-outbound-nat-rule&#34;&gt;6. Create Outbound NAT rule.&lt;/h2&gt;&#xA;&lt;p&gt;Most Wireguard VPN providers will require you to configure outbound NAT, and AirVPN is no exception.&lt;/p&gt;&#xA;&lt;p&gt;Go to Firewall &amp;gt; NAT &amp;gt; Outbound and add a rule.&lt;/p&gt;&#xA;&lt;p&gt;Configure only the following settings and leave everything else default.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source Address: LAN net (or whatever you&amp;#39;re using.)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Description: Outbound NAT for AirVPN&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;7-configure-policy-routing&#34;&gt;7. Configure Policy Routing&lt;/h2&gt;&#xA;&lt;p&gt;How we&amp;rsquo;re going to accomplish this is we&amp;rsquo;re going to create an alias for the devices we want to route out over the VPN tunnel.&lt;/p&gt;&#xA;&lt;p&gt;Call it VPN_Required or whatever you like.&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;ve created the alias, navigate to Firewall &amp;gt; Rules &amp;gt; Your network.&lt;/p&gt;&#xA;&lt;p&gt;Create a pass rule with the following settings defined:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: LAN&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source: VPN_Required&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Gateway: AIRVPN_GW&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Advanced features:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  Set local tag: vpntraffic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Next head to Rules &amp;gt; Floating and define a Block rule.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: Your WAN interface&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Source: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: Any&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Advanced features:&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  Match local tag: vpntraffic&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This block rule will serve as a &amp;ldquo;kill switch&amp;rdquo; preventing our VPN traffic from leaking if the tunnel goes down for some reason.&lt;/p&gt;&#xA;&lt;h2 id=&#34;8-test-it&#34;&gt;8. Test It&lt;/h2&gt;&#xA;&lt;p&gt;I recommend testing the connection at this point. Add your current device&amp;rsquo;s IP address to the alias you&amp;rsquo;re using for policy routing for testing purposes.&lt;/p&gt;&#xA;&lt;p&gt;Go to sites like &lt;a href=&#34;https://ipleak.net/&#34;&gt;https://ipleak.net/&lt;/a&gt; and make sure that everything is reported correctly. Make sure you don&amp;rsquo;t have any DNS leaks, either - it should show DNS servers in the same region as the AirVPN server that you chose.&lt;/p&gt;&#xA;&lt;h2 id=&#34;9-bonus-points---port-forwarding&#34;&gt;9. Bonus Points - Port Forwarding&lt;/h2&gt;&#xA;&lt;p&gt;If you have a need for port forwarding, AirVPN supports up to 5 ports per account.&lt;/p&gt;&#xA;&lt;p&gt;Head on back to the Client Area on their website and click on Ports.&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;If you&amp;rsquo;re forwarding ports for a protocol like Bittorrent, you&amp;rsquo;ll need to use the &lt;code&gt;:1&lt;/code&gt; pool of addresses.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;I suggest using AirVPN&amp;rsquo;s tool on the same page to find a free port in that range.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img alt=&#34;AirVPN port search tool&#34; loading=&#34;lazy&#34; src=&#34;https://blog.ssb-tech.net/posts/airvpn-on-opnsense/images/airvpn-port-checker.png&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Once you&amp;rsquo;ve determined which port to use, configure it for yourself. Configure which device it&amp;rsquo;s for, set the protocol to TCP+UDP.&lt;/p&gt;&#xA;&lt;p&gt;I recommend using ipv4 only.&lt;/p&gt;&#xA;&lt;p&gt;On Opnsense, configure a rule on the airvpn_wg interface. (Firewall &amp;gt; Rules &amp;gt; airvpn_wg)&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Action: Pass&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: TCP/UDP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: The IP address of your box of Linux ISOs.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Port: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Reply-To: AIRVPN_GW&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You&amp;rsquo;ll also want to configure a port forward under NAT &amp;gt; Port Forward.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Interface: airvpn_wg&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Protocol: TCP/UDP&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination: airvpn_wg address&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Destination port range: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Redirect target IP: The IP address of your box of Linux ISOs.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;Redirect target port: the port you defined in AirVPN.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now, in your Bittorrent client, make sure you turn off port randomization, and set the port to the same one.&lt;/p&gt;&#xA;&lt;p&gt;You may also have to allow that port through the system firewall, if there is one.&lt;/p&gt;&#xA;&lt;p&gt;If you&amp;rsquo;re running something like Transmission in Docker, don&amp;rsquo;t forget to publish the port in your docker compose.&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
