# Hotspot mode with VPN bridge

**URL:** https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293
**Category:** General Discussion
**Created:** [30 May 2022 20:43 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293 "2022-05-30T20:43:23Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![zackdvd](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/z/b38774/32.png) [@zackdvd](https://dietpi.com/forum/u/zackdvd)
#### Post date: [30 May 2022 20:43 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/1 "2022-05-30T20:43:23Z")

</div>

Hi,

I want to setup a dietpi which is accessible via wifi, gets its internet connection via eth0 (hotspot mode) BUT also can connect to a VPN.  
Second requirement: It should ONLY then provide internet access when VPN is connected.

I just made a fresh dietpi installation on RPI 4.  
I installed dietpis hotspot mode and it works just fine.  
I also installed (apt-get) vpnc to connect to another network (remote fritz box offering VPN service). This also works from the dietpi itself, but not from wifi clients.  
And I want to somehow stop accessing internet for wifi clients, when VPN is not connected.

vpnc starts up tun0 device when up and connected.

Thank you for any help on that!

Best,  
Zack

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [30 May 2022 21:29 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/2 "2022-05-30T21:29:44Z")

</div>

Hi, if I’m not mistaken you would need to setup `iptable` rules to allow forwarding the network traffic towards the `tun0` interface. Something like this should do

```auto
iptables -t nat -A POSTROUTING -s 192.168.42.0/24 -o tun0 -j MASQUERADE
iptables -A FORWARD -i tun0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i wlan0 -o tun0 -j ACCEPT

```

and to save stuff

```auto
iptables-save > /etc/iptables.ipv4.nat

```

But @trendy is more an expert than I’m and probably has some better ideas. 😃

---

<div class="post-metadata">

### Author: ![zackdvd](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/z/b38774/32.png) [@zackdvd](https://dietpi.com/forum/u/zackdvd)
#### Post date: [31 May 2022 19:31 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/3 "2022-05-31T19:31:28Z")

</div>

Thank you Joulinar!  
This is an awesome community here!

Especially the last command brought me to the idea to have a look into the existing content of the file, so I just changed every _eth0_ to _tun0_ in _/etc/iptables.ipv4.nat_ and it works.

Great solution, easy when you know where to look 🙂

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [31 May 2022 20:35 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/4 "2022-05-31T20:35:42Z")

</div>

Thx for sharing. Goot to know it ia working.

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [1 June 2022 06:05 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/5 "2022-06-01T06:05:06Z")

</div>

> [@Joulinar](#):
>
> ```auto
> iptables -A FORWARD -i tun0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
> iptables -A FORWARD -i tun0 -o wlan0 -j ACCEPT
> 
> ```

As it is, the second rule is making the first redundant. And you don’t want to allow everything from vpn to lan.

```auto
iptables -A FORWARD -i tun0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i wlan0 -o tun0 -j ACCEPT

```

This would be more sensible.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [1 June 2022 07:40 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/6 "2022-06-01T07:40:38Z")

</div>

@trendy should we adjust our install procedure for this part?

> <https://github.com/MichaIng/DietPi/blob/master/dietpi/dietpi-software#L8250-L8256>

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [1 June 2022 08:25 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/7 "2022-06-01T08:25:23Z")

</div>

No, this part is correct. The [snippet](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/5) in the previous post had in both rules the source as the tunnel interface.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [1 June 2022 08:52 UTC](https://dietpi.com/forum/t/hotspot-mode-with-vpn-bridge/13293/8 "2022-06-01T08:52:50Z")

</div>

Ah I see. It was me mixing the interfaces. I just corrected it above. Thx for pointing it out.
