lede-packages-rs

git clone git://archive.git.mtrnord.blog/MTRNord/lede-packages-rs.git
Log | Files | Refs | README | LICENSE

README.md (7402B)


      1 # VPN Bypass
      2 A simple PROCD-based vpnbypass service for OpenWrt/LEDE Project. Useful if your router accesses internet thru VPN client/tunnel, but you want specific traffic (ports, IP ranges, domains or local IP ranges) to be routed outside of this tunnel.
      3 
      4 ## Features
      5 - Allows to define local ports so that traffic to them is routed outside of the VPN tunnel (by default routes Plex Media Server traffic (port 32400) outside of the VPN tunnel).
      6 - Allows to define IPs/subnets in local network so that their traffic is routed outside of the VPN tunnel (by default routes traffic from 192.168.1.81-192.168.1.87 outside of the VPN tunnel).
      7 - Allows to define remote IPs/ranges that they are accessed outside of the VPN tunnel (by default routes LogmeIn Hamachi traffic (25.0.0.0/8) outside of the VPN tunnel).
      8 - Allows to define list of domain names which are accessed outside of the VPN tunnel (useful for Netflix, Hulu, etc).
      9 - Doesn't stay in memory -- creates the iptables rules which are automatically updated on WAN up/down.
     10 - Has a companion package (luci-app-vpnbypass) so everything can be configured with Web UI.
     11 - Proudly made in Canada, using locally-sourced electrons.
     12 
     13 ## Screenshot (luci-app-vpnbypass)
     14 ![screenshot](https://raw.githubusercontent.com/stangri/screenshots/master/vpnbypass/screenshot02.png "screenshot")
     15 
     16 ## Requirements
     17 This service requires following packages to be installed on your router: ```ipset``` and ```iptables```. Additionally, if you want to use Domain Bypass feature, you need to install ```dnsmasq-full``` (```dnsmasq-full``` requires you uninstall ```dnsmasq``` first).
     18 
     19 To fully satisfy the requirements for both IP/Port VPN Bypass and Domain Bypass features connect to your router via ssh and run the following commands:
     20 ```sh
     21 opkg update; opkg remove dnsmasq; opkg install ipset iptables dnsmasq-full
     22 ```
     23 
     24 To satisfy the requirements for just IP/Port VPN Bypass connect to your router via ssh and run the following commands:
     25 ```sh
     26 opkg update; opkg install ipset iptables
     27 ```
     28 
     29 #### Unmet dependencies
     30 If you are running a development (trunk/snapshot) build of OpenWrt/LEDE Project on your router and your build is outdated (meaning that packages of the same revision/commit hash are no longer available and when you try to satisfy the [requirements](#requirements) you get errors), please flash either current LEDE release image or current development/snapshot image.
     31 
     32 ## How to install
     33 <!---
     34 #### From Web UI/Luci
     35 Navigate to System->Software page on your router and then perform the following actions:
     36 1. Click "Update Lists"
     37 2. Wait for the update process to finish.
     38 3. In the "Download and install package:" field type ```vpnbypass luci-app-vpnbypass```
     39 4. Click "OK" to install ```vpnbypass``` and ```luci-app-vpnbypass```
     40 
     41 If you get an ```Unknown package 'vpnbypass'``` error, your router is not set up with the access to repository containing these packages and you need to add custom repository to your router first.
     42 
     43 #### From console/ssh
     44 --->
     45 Please make sure that the [requirements](#requirements) are satisfied and install ```vpnbypass``` and ```luci-app-vpnbypass``` from Web UI or connect to your router via ssh and run the following commands:
     46 ```sh
     47 opkg update
     48 opkg install vpnbypass luci-app-vpnbypass
     49 ```
     50 If these packages are not found in the official feed/repo for your version of OpenWrt/LEDE Project, you will need to [add a custom repo to your router](#add-custom-repo-to-your-router) first.
     51 
     52 #### Add custom repo to your router
     53 If your router is not set up with the access to repository containing these packages you will need to add custom repository to your router by connecting to your router via ssh and running the following commands:
     54 
     55 ###### OpenWrt CC 15.05.1
     56 ```sh
     57 opkg update; opkg install wget libopenssl
     58 echo -e -n 'untrusted comment: public key 7ffc7517c4cc0c56\nRWR//HUXxMwMVnx7fESOKO7x8XoW4/dRidJPjt91hAAU2L59mYvHy0Fa\n' > /tmp/stangri-repo.pub && opkg-key add /tmp/stangri-repo.pub
     59 ! grep -q 'stangri_repo' /etc/opkg/customfeeds.conf && echo 'src/gz stangri_repo https://raw.githubusercontent.com/stangri/openwrt-repo/master' >> /etc/opkg/customfeeds.conf
     60 opkg update
     61 ```
     62 
     63 ###### LEDE Project and OpenWrt DD trunk
     64 ```sh
     65 opkg update; opkg install uclient-fetch libustream-mbedtls
     66 echo -e -n 'untrusted comment: public key 7ffc7517c4cc0c56\nRWR//HUXxMwMVnx7fESOKO7x8XoW4/dRidJPjt91hAAU2L59mYvHy0Fa\n' > /tmp/stangri-repo.pub && opkg-key add /tmp/stangri-repo.pub
     67 ! grep -q 'stangri_repo' /etc/opkg/customfeeds.conf && echo 'src/gz stangri_repo https://raw.githubusercontent.com/stangri/openwrt-repo/master' >> /etc/opkg/customfeeds.conf
     68 opkg update
     69 ```
     70 
     71 ## Default Settings
     72 Default configuration has service disabled (use Web UI to enable/start service or run ```uci set vpnbypass.config.enabled=1```) and routes Plex Media Server traffic (port 32400) outside of the VPN tunnel, routes LogmeIn Hamachi traffic (25.0.0.0/8) outside of the VPN tunnel and also routes internet traffic from local IPs 192.168.1.81-192.168.1.87 outside of the VPN tunnel. You can safely delete these example rules if they do not apply to you.
     73 
     74 ## Documentation / Discussion
     75 Please head to [LEDE Project Forum](https://forum.lede-project.org/t/vpn-bypass-split-tunneling-service-luci-ui/1106) for discussions of this service.
     76 
     77 #### Bypass Domains Format/Syntax
     78 Domain lists should be in following format/syntax: ```/domain1.com/domain2.com/vpnbypass```. Please don't forget the leading ```/``` and trailing ```/vpnbypass```. There's no validation if you enter something incorrectly -- it just won't work. Please see [Notes/Known Issues](#notesknown-issues) if you want to edit this setting manually, without Web UI.
     79 
     80 ## What's New
     81 1.3.0
     82 - No longer depends on hardcoded WAN interface name (```wan```) works with other interface names (like ```wwan```).
     83 - Table ID, IPSET name and FW_MARK as well as FW_MASK can be defined in config file.
     84 - Uses iptables, not ip rules for handling local IPs/ranges.
     85 - More reliable creation/destruction of VPNBYPASS iptables chain.
     86 - Updated Web UI enables/start and stops service.
     87 - Beautified output.
     88 
     89 1.2.0
     90 - More elegant handling of iptables (thanks [@hnyman](https://github.com/hnyman) and [@tohojo](https://github.com/tohojo)!).
     91 
     92 1.1.1
     93 - More reliable way of obtaining WAN gateway on boot (thanks [@dibdot](https://github.com/dibdot) for the hint!).
     94 
     95 1.1.0:
     96 - Detects individual IP addresses in the config and converts them to subnet automatically.
     97 - Proper implementation of reload on vpnbypass config change.
     98 
     99 1.0.0:
    100 - Hotplug script created during install.
    101 
    102 0.1.0:
    103 - Package built.
    104 - Support for user-defined ports implemented.
    105 - Support for user-defined routes implemented.
    106 - Support for user-defined local ranges implemented.
    107 
    108 0.0.1:
    109 - Initial release.
    110 
    111 ## Notes/Known Issues
    112 1. Domains to be accessed outside of VPN tunnel are handled by dnsmasq and thus are not defined in ```/etc/config/vpnpass```, but rather in ```/etc/config/dhcp```. To add/delete/edit domains you can use VPN Bypass Web UI or you can edit ```/etc/config/dhcp``` manually or run following commands:
    113 ```sh
    114 uci add_list dhcp.@dnsmasq[-1].ipset='/github.com/plex.tv/google.com/vpnbypass'
    115 uci add_list dhcp.@dnsmasq[-1].ipset='/hulu.com/netflix.com/nhl.com/vpnbypass'
    116 uci commit dhcp
    117 /etc/init.d/dnsmasq restart
    118 ```
    119 This feature requires ```dnsmasq-full``` to work. See [Requirements](#requirements) paragraph for more details.