# Need VPN iproute help

**URL:** https://dietpi.com/forum/t/need-vpn-iproute-help/19089
**Category:** Troubleshooting
**Created:** [27 January 2024 15:31 UTC](https://dietpi.com/forum/t/need-vpn-iproute-help/19089 "2024-01-27T15:31:44Z")
**Posts on this page:** 1
**Showing post:** 10

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [29 January 2024 18:38 UTC](https://dietpi.com/forum/t/need-vpn-iproute-help/19089/10 "2024-01-29T18:38:59Z")

</div>

Given the requirement to route only the hotspot over vpn, I would suggest the following.

1. Filter the default gateway from the OpenVPN client.

```auto
cat << EOF >> /etc/openvpn/client.conf
pull-filter ignore redirect-gateway
route-nopull
EOF

```

1. Now your default gateway remains the eth1 after the VPN is up.
2. Isolate the hostspot and route it over the VPN

```auto
ip rule add from 192.168.42.0/24 lookup 42
ip route add default via 10.6.19.1 dev tun1 table 42

```

1. Fix the firewall

```auto
iptables -t nat -A POSTROUTING -s 192.168.42.0/24 -o tun1 -j MASQUERADE
iptables -t filter -A FORWARD -i wlan0 -o tun1 -j ACCEPT

```

1. You probably want to delete the other firewall rules to allow from wlan0 to eth1 if you want them isolated.

---

_[View the full topic](https://dietpi.com/forum/t/need-vpn-iproute-help/19089)._
