I'm trying to make one single device use a TAP VPN without affecting the other devices. I seem to be able to do the first part but not the second.
SiteA: AX88 with 388.2.2 and two servers, one a TUN VPN and one a TAP VPN.
SiteB: AC86 with 386.11 and two clients, one a TUN client to SiteA, the other a TAP client to SiteA.
The TUN connection between SiteA and SiteB is two way but split: devices on each site reach the other site over the TUN but go out to the internet directly and not over the tunnel. That works fine. I have a VPN director rule that sets one device on SiteB to use the tunnel only. That works fine.
I want one and only one device on SiteB to use the TAP tunnel exclusively. If I activate the TAP tunnel to SiteA, that works, but in short order all the other devices at SiteB start over minutes to hours to go bonkers, pulling SiteA addresses and losing DNS.
I've tried a VPN Director rule but from what I've read it only handles TUN connections. I've tried YazGuestWifi, but the problem is still when I activate the TAP tunnel. I don't think I can use a custom client configuration because that is just based on the TAP client, not the device using the TAP client (although maybe?).
So I'm looking for a hint to do something on one side or the other to keep the other SiteB clients from being messed up.
SiteA: AX88 with 388.2.2 and two servers, one a TUN VPN and one a TAP VPN.
SiteB: AC86 with 386.11 and two clients, one a TUN client to SiteA, the other a TAP client to SiteA.
The TUN connection between SiteA and SiteB is two way but split: devices on each site reach the other site over the TUN but go out to the internet directly and not over the tunnel. That works fine. I have a VPN director rule that sets one device on SiteB to use the tunnel only. That works fine.
I want one and only one device on SiteB to use the TAP tunnel exclusively. If I activate the TAP tunnel to SiteA, that works, but in short order all the other devices at SiteB start over minutes to hours to go bonkers, pulling SiteA addresses and losing DNS.
I've tried a VPN Director rule but from what I've read it only handles TUN connections. I've tried YazGuestWifi, but the problem is still when I activate the TAP tunnel. I don't think I can use a custom client configuration because that is just based on the TAP client, not the device using the TAP client (although maybe?).
So I'm looking for a hint to do something on one side or the other to keep the other SiteB clients from being messed up.