What's new

Port forwarding missing implementation

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

foosy

New Around Here
If you define port forwarding rules for certain devices, and such devices are also selected for VPN, then port forwarding rules are ignored.

Use case is such: I have devices that need to use certain ports. when using them without VPN, everything works OK.
When using those same devices through a VPN client , port forwarding rules are ignored. NAT is applied through VPN connection with disregard to rules.
Now granted, not all OpenVPN support all ports but for those that do, this prevents using those devices with VPN.

Required Fix: implement port forwarding rules for connections using VPN clients.
 
This is a known limitation of using VPN clients. The router can't send port forwarded replies out through the WAN when you've configured it to send all traffic from that client through the VPN.
 
Last edited:
That is exactly the issue: I don’t want to port forward through the WAn. I want it through the VPN.
The router is NATing all traffic through the VPN. For specific devices I want it to do port forwarding. This can be implemented by specifying port forwarding rules through VPN, or better by implementing defined rules also for VPN traffic.
 
In which case contact Asus support about it. SNB is not an Asus support channel so no one from Asus will see your post.
 
I thought this limitation would be of interest to people in the forum.
The same limitation has been discussed in the Asuswrt-Merlin subforum for many years (where the firmware offers possible workarounds).
 
I came here to research for this feature as well. Last night I was playing around with my GliNet travel router and it does have Wireguard support as well as port forwarding UI and using the wireguard interface when implementing the rules to forward port to a wgclient interface. I kind of wish Asus would add this option as well. I assume it's a bunch of iptables as PostUp in the wg0 config file.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top