From owner-freebsd-questions@freebsd.org Sat Mar 5 10:55:40 2016 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id F253C9DBAD9 for ; Sat, 5 Mar 2016 10:55:40 +0000 (UTC) (envelope-from mmatalka@gmail.com) Received: from mail-wm0-x233.google.com (mail-wm0-x233.google.com [IPv6:2a00:1450:400c:c09::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 8DEC6CA1 for ; Sat, 5 Mar 2016 10:55:40 +0000 (UTC) (envelope-from mmatalka@gmail.com) Received: by mail-wm0-x233.google.com with SMTP id l68so23307361wml.0 for ; Sat, 05 Mar 2016 02:55:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:to:subject:date:message-id:user-agent:mime-version; bh=Pb+YrrkvIP8jjE9OOIBq1wj+SFnGrzoLAY4ipYjDpx8=; b=Baiz3cWRo+VPGE6t2yAWR9lxqhc2LBcWl8KTbuuAyTVqY6Sq73m+FzhBAYBTbFOplQ 2b2iRknn0XjLt34OiX7JkL/wIBS+gwXJUvAcWZQl1nwYKgncNYlX1BfBhhsmQMRm+YNX 002D+kxCPnR5iC0XFebucGrMxz67pYhvT91nyw5afTFV8UNLERifzqgDDDDKttVFTm/Y UcymsQGsMH7jjQ+QopDn9yimKtNREJ+ajFT5WrRaW0hU+LXmzJ5hzbJqO0114RzlDW7T 6jM5VfAsRSOLdFaOOmPwf7mwTSc9v/rksDHxrz0ANPlArIBkrHyZ7EgLG9mRUgZitbak gARg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:subject:date:message-id:user-agent :mime-version; bh=Pb+YrrkvIP8jjE9OOIBq1wj+SFnGrzoLAY4ipYjDpx8=; b=N7TF2Mx5OubFc/HTa2fwxU2FbXvE8PmeduI2rhe2T23FQh+hhtUNUuZ7bVYlJlW/mZ ZjwX5oa+qGD0s8mUmDR1QA03TDF9f++WbrEHBMMLOcDasxLnVPgwx4/UicYaGfIRjAWL Wv44xomw7xGmpwBXMYicPhyWWOeCIQKCoBYFVLJD0LVlIrZh/rOjOOq/Qu6mGPdDu4Ih 7w3DqApDCW8JT5BgLvBC58vtFOEhVZBaaQkPaz+yUYNKZpLCidMXQS6IWrD833GzMGPq 6suWqknzcc11L7/8yOad9fThJuWrDOheDpPH1wmSvKMIZMJmJvvf4SiFvQfUYRRVDLqs zeZg== X-Gm-Message-State: AD7BkJIlISoIY0RgqKBHhaSf7RIzCu97sAkqZdL9fs3uxvRzKDphJE+qEq7UU9JiqlwAEg== X-Received: by 10.194.2.76 with SMTP id 12mr13621743wjs.28.1457175338797; Sat, 05 Mar 2016 02:55:38 -0800 (PST) Received: from localhost ([37.153.108.22]) by smtp.gmail.com with ESMTPSA id xx3sm7604896wjc.32.2016.03.05.02.55.37 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 05 Mar 2016 02:55:37 -0800 (PST) From: Malcolm Matalka To: freebsd-questions@freebsd.org Subject: Want to NAT over VPN but not the gateway's own traffic Date: Sat, 05 Mar 2016 10:55:19 +0000 Message-ID: <86h9glfb3c.fsf@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 05 Mar 2016 10:55:41 -0000 I'm trying to have the following setup: I have a host that is acting as a WiFi access point and then NATing traffic to the internet. That host is running an OpenVPN client. So wlan0 traffic is NAT'd to tun0. That is exactly what I want. However, I would like to keep this setup of the WiFi AP going through the VPN but the traffic of the machine itself to go not go through the VPN. Is this possible? How? I'm not sure what information I actually need to get proper help. /Malcolm