Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.comm > #741 > unrolled thread

VPN service that offers NOT "all traffic through VPN"?

Started byDaveC <invalid@invalid.net>
First post2012-03-24 21:17 -0700
Last post2012-03-31 08:10 -0700
Articles 10 on this page of 50 — 10 participants

Back to article view | Back to comp.sys.mac.comm


Contents

  VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-24 21:17 -0700
    Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 00:41 -0400
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-24 22:09 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-25 08:42 -0400
        Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 13:20 -0400
          Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-25 17:44 +0000
            Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 11:14 -0700
            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:14 -0400
              Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:29 -0400
          Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 11:13 -0700
            Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-25 17:39 -0400
              Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 21:11 -0700
                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-26 00:40 -0400
                  Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-26 01:08 -0400
                    Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 23:16 -0700
                      Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-26 07:19 +0000
                        Re: VPN service that offers NOT "all traffic through VPN"? Paul Sture <paul@sture.ch> - 2012-03-26 10:55 +0200
                      Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-26 16:10 -0400
                        Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 22:18 -0700
                          Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-27 07:09 +0000
                          Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-27 04:46 -0400
                          Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 16:39 +0000
                            Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-27 17:14 +0000
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:00 +0000
                            Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-27 13:45 -0400
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:04 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:48 -0400
                            Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 13:23 -0700
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:44 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 16:01 -0700
                                  Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-27 22:52 -0400
                                    Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-28 07:56 -0400
                                      Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-28 15:47 -0400
                                  Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:54 -0400
                                    Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-28 03:42 +0000
                                      Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-28 07:58 -0400
                                      Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-28 20:59 -0400
                            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:45 -0400
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-28 03:43 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-28 21:05 -0400
            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:28 -0400
    Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-25 01:48 -0400
    Re: VPN service that offers NOT "all traffic through VPN"? David Sankey <David.Sankey@stfc.ac.uk> - 2012-03-26 09:58 +0100
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 08:31 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 08:43 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-26 18:09 +0000
    Re: VPN service that offers NOT "all traffic through VPN"? ~± <info@nospam.net> - 2012-03-27 00:00 +0200
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 09:18 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? ~± <info@nospam.net> - 2012-03-27 22:54 +0200
    Re: VPN service that offers NOT "all traffic through VPN"? Maury Markowitz <maury.markowitz@gmail.com> - 2012-03-31 08:10 -0700

Page 3 of 3 — ← Prev page 1 2 [3]


#752

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-25 18:28 -0400
Message-ID<jko65v$goo$1@dont-email.me>
In reply to#748
On 03-25-2012 14:13, DaveC wrote:
> Things are slowed down somewhat when using the service. And my bandwidth with

They claim the difference is negligible.

> their service will be less if I'm sending mail and other (non-BBC)

I suspect your ISP affects that more than they do.

> When I inquire at a web site about some product, I'm always shown prices in
> GBP not USD. I have to turn off the VPN and try again. If I'm streaming a

That's a good reason.

> Not crucial stuff, but annoying. If I'm paying for a service, I want to be
> able to customize it to my liking.

If you do in a shell,

ifconfig -a

how many IP addresses do you see with and without VPN?  If an extra 
appears when you enable VPN, then I think you can configure your routing 
tables to make that one the gateway for your BBC IP block,
and the default be the one that you use when VPN is off.

On the other hand, A is you, B is the WiTopia server near you, C is the 
WiTopia server that does the decryption, and D is the target of your 
request.

A -> B -> C -> D

You get to choose where C is.  And if you do't choose, it would be 
stupid of them not to automatically put it as close to D as possible.

On the third hand, if you are _ONLY_ using it for http requests to BBC, 
then a simple proxy in UK would be a better solution.

-- 
Wes Groleau

   “Beware the barrenness of a busy life.”
                                — Socrates

[toc] | [prev] | [next] | [standalone]


#744

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-03-25 01:48 -0400
Message-ID<4f6eb190$0$1496$c3e8da3$92d0a893@news.astraweb.com>
In reply to#741
DaveC wrote:
> Looking for a VPN service that offers an option of routing some -- but not 
> all -- network traffic through the VPN. 


On my mac, I can setup a VPN to the internet with my ISP's VPN server.
But the  Mac honours the local route to my 10.* LAN subnet wich does not
go through the VPN.

I guess you could build static routes to Google's IP addresses via your
standard interface (en0 or en1) and then let the VPN connection on the
mac take care of everything else.

[toc] | [prev] | [next] | [standalone]


#760

FromDavid Sankey <David.Sankey@stfc.ac.uk>
Date2012-03-26 09:58 +0100
Message-ID<David.Sankey-9FCE0C.09580026032012@news.eternal-september.org>
In reply to#741
In article 
<0001HW.CB93EA7800A72979B02919BF@news.eternal-september.org>,
 DaveC <invalid@invalid.net> wrote:

> Looking for a VPN service that offers an option of routing some -- but not 
> all -- network traffic through the VPN. 
> 
> I'd like to use VPN for some web sites, but not for general Googling and 
> such. 

Assuming you're using PPTP, if the sites that you want to reach over the 
VPN are all on the same network as the VPN server, then it's trivial - 
you just deselect "Send all traffic over VPN connection" in Options tab 
of the "Advanced..." button from the VPN configuration pane.

Otherwise you have to think a bit more.

First question is whether your default route is over the VPN or not 
(this defines your setting of the above flag).

Then you need to decide which networks you want to route the other way, 
and for these networks specify static routes.

Where you want to do this is in a script called /etc/ppp/ip-up, which is 
run automatically when you start the VPN.

Google for /etc/ppp/ip-up to answer all your questions.

Dave

[toc] | [prev] | [next] | [standalone]


#763

FromDaveC <invalid@invalid.net>
Date2012-03-26 08:31 -0700
Message-ID<0001HW.CB95D9F8011B4C12B02919BF@news.eternal-september.org>
In reply to#760
> Google for /etc/ppp/ip-up to answer all your questions.
> 
> Dave

I found this:
---
Create the file /etc/ppp/ip-up with following content:

     #!/bin/sh
     /sbin/route add SUBNET $5

replacing SUBNET with subnet, you want to route through VPN (for ex.         
192.168.0.0/16)

execute as root:
chmod 0755 /etc/ppp/ip-up

This file will be executed each time you connect to VPN.
---
I substituted "SUBNET" with ".co.uk". It's not routing any traffic through 
the VPN.

How (can I?) change the subnet in the above file such that it routes based on 
multiple domains (ie, *.co.uk* or *.ru*, etc.)?

Thanks.

[toc] | [prev] | [next] | [standalone]


#764

FromDaveC <invalid@invalid.net>
Date2012-03-26 08:43 -0700
Message-ID<0001HW.CB95DCA2011BEBD4B02919BF@news.eternal-september.org>
In reply to#763
Also tried this:

< 
http://stackoverflow.com/questions/3703849/possible-to-configure-os-x-vpn-to-
split-traffic-between-vpn-and-local-interface>

No joy.

[toc] | [prev] | [next] | [standalone]


#765

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-03-26 18:09 +0000
Message-ID<slrnjn1c10.c62.gsm@cable.mendelson.com>
In reply to#763
DaveC wrote:

> replacing SUBNET with subnet, you want to route through VPN (for ex.         
> 192.168.0.0/16)

It has to be numeric and have zeros in the octets that are reserved for 
routing.

In plain English, if the number after the slash (the number of bits used to
make a netmask) is 8, then the last number must be zero, eg. 192.168.1.0/8.
If it is 16, then the last 2, e.g. 192.168.0.0/16. If it is 24 then 
192.0.0.0/24. 

32 would be the default route, 0.0.0.0/32.

If you look hard enough you should be able to find a list of IP address
allocated to the UK.

Geoff.

-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM
My high blood pressure medicine reduces my midichlorian count. :-(

[toc] | [prev] | [next] | [standalone]


#767

From~± <info@nospam.net>
Date2012-03-27 00:00 +0200
Message-ID<jkqouc$er2$1@speranza.aioe.org>
In reply to#741
On 25/3/12 06:17 , DaveC wrote:

> Looking for a VPN service that offers an option of routing some -- but not
> all -- network traffic through the VPN.
>
> I'd like to use VPN for some web sites, but not for general Googling and
> such.
>
> Anyone have *experience* with a service they can *recommend*?
>
> If there's a better forum in which to ask this question, just say so...
>
> Thanks.

Have you considered Astrill? Their last beta software seems to offer the 
feature you're looking for:

http://blog.astrill.com/index.php/2012/01/30/astrill-2-7-beta-released/

The beta is almost finished:

https://twitter.com/astrill/status/183688897518252032

BTW: if you're interested to try/subscribe the service I can "invite" 
you (referral affiliation).

Bye.

-- 
~±

[toc] | [prev] | [next] | [standalone]


#773

FromDaveC <invalid@invalid.net>
Date2012-03-27 09:18 -0700
Message-ID<0001HW.CB97364E016CF0BFB02919BF@news.eternal-september.org>
In reply to#767
> Have you considered Astrill? Their last beta software seems to offer the 
> feature you're looking for:

-=-=-=-

I've searched a bit and found that there's quite a bit of negative reviews 
about Astrill, particularly their customer service. 

There are lots of other VPN services that are better-rated.

I think I'll pass...

[toc] | [prev] | [next] | [standalone]


#781

From~± <info@nospam.net>
Date2012-03-27 22:54 +0200
Message-ID<jkt9di$hr9$1@speranza.aioe.org>
In reply to#773
On 27/3/12 18:18 , DaveC wrote:

> I've searched a bit and found that there's quite a bit of negative reviews
> about Astrill, particularly their customer service.
>
> There are lots of other VPN services that are better-rated.
>
> I think I'll pass...

OK, it was just a possible solution.

FYI, my experience with its customer service hasn't been bad so far. 
Anyway, this is only one opinion, of course. My two cents.

Bye.

-- 
~±

[toc] | [prev] | [next] | [standalone]


#804

FromMaury Markowitz <maury.markowitz@gmail.com>
Date2012-03-31 08:10 -0700
Message-ID<f0974b4b-1658-408f-be5f-6a01fb25e02f@gw9g2000vbb.googlegroups.com>
In reply to#741
On Mar 25, 12:17 am, DaveC <inva...@invalid.net> wrote:
> I'd like to use VPN for some web sites, but not for general Googling and
> such.
>
> Anyone have *experience* with a service they can *recommend*?

I have experience with a *technology* that offers this, SSL VPN. This
service is built into a number of Cisco and Juniper boxes, and, one
assumes, others as well. Using SSL VPN you first navigate to a web
page and type in your credentials. Once logged in, traffic to a given
set of IP addresses is routed through an SSL link. The traffic does
not have to be web-based, any combination of addresses and ports can
be routed.

How to GET such a service is another issue. There is a product called
OpenVPN that offers it in software, and apparently some sort of
service offering as well. However, I found their web site quite
confusing, and when I called the companies mentioned on the web page
they had no idea what I was talking about.

I have found a number of hosting companies that offer SSL VPN service
in front of their cloud servers. This is a useful solution for many
uses, perhaps your own.

Maury

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | comp.sys.mac.comm


csiph-web