Why can't I route traffic from a specific device through a VPN?

I have an UDM-SE and was playing around with the routing through the VPN with no luck and it’s weird it’s not working.

  • add a VPN client via wireguard. I called this CH since it’s a VPN from ProtonVpn in Switzerland.
  • go to the policy-based routing.
  • add a new one. What to route? All traffic. Source? Any combination (all, network or a single device). Interface? Only appears WAN1 or Secondary WAN2 that is not even connected.

Why doesn’t the interface have my newly created CH VPN client? It seems it only shows up if I define What to route == specific traffic.

All these steps were tried inside the Unifi Android app.

Thanks!

Open the unifi app, go to settings, routing, policy based routing, add new.

What to route? All traffic.
Source? Pick the networks you created for the vpn.
Interface? Select the vpn one.
Fallback? You will most likely want that disabled.

No problem, thanks for the help!

If your interface is not showing up, go back to the vpn section, then vpn client, and make sure the vpn is connected and shows traffic Stats.

This is how I have mine setup and it works flawlessly.

Wait, I didn’t create any network for the VPN, just the VPN client. Not sure what you mean with this. Thanks!

That’s the thing, the last step where you select the interface only shows wan and secondary wan. If I select only portions of the traffic like domains, countries, etc then it shows up

Ok, what I have is a separate network with its own vlan and dhcp, I put all clients I want on that network and then route that network traffic over the vpn.

That’s strange, I have a wire guard setup, a separate network, and a separate wifi setup, and all traffic from any client that connects to the wifi network automatically has all traffic routed over the vpn. Same goes for any wired client you connect to and assign it an ip from the network range.

It seems to be an app issue. I was able to set to the VPN interface via the Web interface

Ah ok, I am on the beta track for the unifi app, maybe it’s something fixed there already? Who knows!

Yep, I see it as well, I didn’t notice it because it only hides one of them, so if you have 2 entries you see one entry and it just so happened to be the entry I use.