Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.comm > #741 > unrolled thread

VPN service that offers NOT "all traffic through VPN"?

Started byDaveC <invalid@invalid.net>
First post2012-03-24 21:17 -0700
Last post2012-03-31 08:10 -0700
Articles 20 on this page of 50 — 10 participants

Back to article view | Back to comp.sys.mac.comm


Contents

  VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-24 21:17 -0700
    Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 00:41 -0400
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-24 22:09 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-25 08:42 -0400
        Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 13:20 -0400
          Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-25 17:44 +0000
            Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 11:14 -0700
            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:14 -0400
              Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:29 -0400
          Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 11:13 -0700
            Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-25 17:39 -0400
              Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 21:11 -0700
                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-26 00:40 -0400
                  Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-26 01:08 -0400
                    Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-25 23:16 -0700
                      Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-26 07:19 +0000
                        Re: VPN service that offers NOT "all traffic through VPN"? Paul Sture <paul@sture.ch> - 2012-03-26 10:55 +0200
                      Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-26 16:10 -0400
                        Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 22:18 -0700
                          Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-27 07:09 +0000
                          Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-27 04:46 -0400
                          Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 16:39 +0000
                            Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-27 17:14 +0000
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:00 +0000
                            Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-27 13:45 -0400
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:04 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:48 -0400
                            Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 13:23 -0700
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-27 20:44 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 16:01 -0700
                                  Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-27 22:52 -0400
                                    Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-28 07:56 -0400
                                      Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-28 15:47 -0400
                                  Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:54 -0400
                                    Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-28 03:42 +0000
                                      Re: VPN service that offers NOT "all traffic through VPN"? Warren Oates <warren.oates@gmail.com> - 2012-03-28 07:58 -0400
                                      Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-28 20:59 -0400
                            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-27 22:45 -0400
                              Re: VPN service that offers NOT "all traffic through VPN"? Patty Winter <patty1@wintertime.com> - 2012-03-28 03:43 +0000
                                Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-28 21:05 -0400
            Re: VPN service that offers NOT "all traffic through VPN"? Wes Groleau <Groleau+news@FreeShell.org> - 2012-03-25 18:28 -0400
    Re: VPN service that offers NOT "all traffic through VPN"? JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-03-25 01:48 -0400
    Re: VPN service that offers NOT "all traffic through VPN"? David Sankey <David.Sankey@stfc.ac.uk> - 2012-03-26 09:58 +0100
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 08:31 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-26 08:43 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-03-26 18:09 +0000
    Re: VPN service that offers NOT "all traffic through VPN"? ~± <info@nospam.net> - 2012-03-27 00:00 +0200
      Re: VPN service that offers NOT "all traffic through VPN"? DaveC <invalid@invalid.net> - 2012-03-27 09:18 -0700
        Re: VPN service that offers NOT "all traffic through VPN"? ~± <info@nospam.net> - 2012-03-27 22:54 +0200
    Re: VPN service that offers NOT "all traffic through VPN"? Maury Markowitz <maury.markowitz@gmail.com> - 2012-03-31 08:10 -0700

Page 1 of 3  [1] 2 3  Next page →


#741 — VPN service that offers NOT "all traffic through VPN"?

FromDaveC <invalid@invalid.net>
Date2012-03-24 21:17 -0700
SubjectVPN service that offers NOT "all traffic through VPN"?
Message-ID<0001HW.CB93EA7800A72979B02919BF@news.eternal-september.org>
Looking for a VPN service that offers an option of routing some -- but not 
all -- network traffic through the VPN. 

I'd like to use VPN for some web sites, but not for general Googling and 
such. 

Anyone have *experience* with a service they can *recommend*?

If there's a better forum in which to ask this question, just say so...

Thanks.

[toc] | [next] | [standalone]


#742

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-25 00:41 -0400
Message-ID<jkm7mh$gbj$1@dont-email.me>
In reply to#741
On 03-25-2012 00:17, DaveC wrote:
> Looking for a VPN service that offers an option of routing some -- but not
> all -- network traffic through the VPN.
>
> I'd like to use VPN for some web sites, but not for general Googling and
> such.
>
> Anyone have *experience* with a service they can *recommend*?

Do you mean a proxy?  A VPN is not normally called a "service."

Virtual Private Network is a way of encrypting all the traffic  between 
to points so that you can use somebody else's network (internet) as 
securely as if you were in the same building behind the same firewall.

A proxy, on the other hand, is a relay point you are required to send 
some subset of your traffic through instead of sending it direct.

-- 
Wes Groleau

Always listen to experts.  They'll tell you
what can't be done and why.  Then do it.
                     — Robert A. Heinlein

[toc] | [prev] | [next] | [standalone]


#743

FromDaveC <invalid@invalid.net>
Date2012-03-24 22:09 -0700
Message-ID<0001HW.CB93F6B600AA07F1B02919BF@news.eternal-september.org>
In reply to#742
> Do you mean a proxy?  A VPN is not normally called a "service."

I tried a service called Witopia which advertises as a VPN service but by 
your definition sounds like it includes a proxy at the destination.

<http://www.witopia.net>

Regardless what it's called (not that a name isn't important (c: ) I want to 
use it for some of the network traffic, not all. 

Thanks for the clarification...

[toc] | [prev] | [next] | [standalone]


#745

FromWarren Oates <warren.oates@gmail.com>
Date2012-03-25 08:42 -0400
Message-ID<4f6f12bd$0$9813$c3e8da3$1cbc7475@news.astraweb.com>
In reply to#743
In article 
<0001HW.CB93F6B600AA07F1B02919BF@news.eternal-september.org>,
 DaveC <invalid@invalid.net> wrote:

> I tried a service called Witopia which advertises as a VPN service but by 
> your definition sounds like it includes a proxy at the destination.
> 
> <http://www.witopia.net>
> 
> Regardless what it's called (not that a name isn't important (c: ) I want to 
> use it for some of the network traffic, not all. 
> 
> Thanks for the clarification...

I dunno, I reckon, if you pay for it, it's a service.

Anyway, what "service" did you try out at Witopia? I have the "pro" 
thing because I consider myslef in a censored country, and it works real 
good too. 

They use Viscosity for SSL, and it puts a little icon in my menubar with 
drop-down menu of all the servers I can use. It connects quickly when I 
want to look at the BBC (say). Disconnects just as fast.

I've also got L2TP which offers a "VPN on Demand" option. Did you look 
into that?
-- 

... do not cover a warm kettle or your stock may sour. -- Julia Child

[toc] | [prev] | [next] | [standalone]


#746

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-25 13:20 -0400
Message-ID<jknk49$390$1@dont-email.me>
In reply to#743
On 03-25-2012 01:09, DaveC wrote:
>> Do you mean a proxy?  A VPN is not normally called a "service."
>
> I tried a service called Witopia which advertises as a VPN service but by
> your definition sounds like it includes a proxy at the destination.
>
> <http://www.witopia.net>
>
> Regardless what it's called (not that a name isn't important (c: ) I want to
> use it for some of the network traffic, not all.

I see, said the blind man.  I'm not a subscriber, but just from their 
main web page, it looks like it is both.  The VPN part prevents your 
local ISP (or anyone using them) from spying on you.  The proxy part
allows any traffic you send through there to have additional processing 
or filtering by them instead of by you (which can include hiding your 
location).

Once the traffic leaves WiTopia, it is still subject to spying, but if 
you are the target, it is much more difficult for the spy to pick you 
out of all the other traffic.

(And of course, you have no way of knowing whether WiTopia or someone 
who hacked into them is spying on you.)

I think ipfirewall(4) or ipfw(8) or route(8) could be used to 
selectively route traffic, but configuration would not be as GUI-simple 
as Apple-provided things.

I haven't used a VPN in seven years, and it wasn't Apple's, but maybe 
WiTopia, if their tech support is as good as they claim, can answer your 
question.

Curious, why do you want to bypass them for some addresses?  Do they do 
things you DON'T want?

-- 
Wes Groleau

   Nutrition for Blokes: Re-engineering your diet for life
   http://www.phlaunt.com/quentin

[toc] | [prev] | [next] | [standalone]


#747

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-03-25 17:44 +0000
Message-ID<slrnjmuma8.12c.gsm@cable.mendelson.com>
In reply to#746
Wes Groleau wrote:

> Curious, why do you want to bypass them for some addresses?  Do they do 
> things you DON'T want?

I haven't used their service, but I can explain why. I'm here, they're there.
Bandwidth to/from severs here is cheap and plentiful. I can max out my
internet connection 24/7 to servers within the country.

Bandwidth outside the country is expensive and hard to get. Lots of it at
8am, when no one is doing anything. Come back at 3pm when kids get home from
school and it starts to slow down. By 8 at night, it's at a crawl.

So if I need to use a VPN or proxy server to make a foreign site think I am
a local user, then it's worth the bandwith and the slow performance to get
something I could not get before.

If I need to get something locally, it makes no sense to send the data up
the pipe to the VPN/proxy server in another country and then have it go
back to the local server and vice versa.

Geoff.


-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM
My high blood pressure medicine reduces my midichlorian count. :-(

[toc] | [prev] | [next] | [standalone]


#749

FromDaveC <invalid@invalid.net>
Date2012-03-25 11:14 -0700
Message-ID<0001HW.CB94AEA600D5248BB02919BF@news.eternal-september.org>
In reply to#747
> If I need to get something locally, it makes no sense to send the data up
> the pipe to the VPN/proxy server in another country and then have it go
> back to the local server and vice versa.
> 
> Geoff.

Said much better than I did...

d.

[toc] | [prev] | [next] | [standalone]


#751

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-25 18:14 -0400
Message-ID<jko5cu$cva$1@dont-email.me>
In reply to#747
On 03-25-2012 13:44, Geoffrey S. Mendelson wrote:
> If I need to get something locally, it makes no sense to send the data up
> the pipe to the VPN/proxy server in another country and then have it go
> back to the local server and vice versa.

But they claim to be fast for any route, plus I would expect your ISP to 
hand you to their server in your country and for that one to be smart 
enough not to send it out of the country unless you asked them to.

-- 
Wes Groleau

    Measure with a micrometer, mark with chalk, and cut with an axe.

[toc] | [prev] | [next] | [standalone]


#753

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-25 18:29 -0400
Message-ID<jko67f$goo$2@dont-email.me>
In reply to#751
On 03-25-2012 18:14, Wes Groleau wrote:
> On 03-25-2012 13:44, Geoffrey S. Mendelson wrote:
>> If I need to get something locally, it makes no sense to send the data up
>> the pipe to the VPN/proxy server in another country and then have it go
>> back to the local server and vice versa.
>
> But they claim to be fast for any route, plus I would expect your ISP to
> hand you to their server in your country and for that one to be smart
> enough not to send it out of the country unless you asked them to.

oops.  I thought they had a server in your country, but they don't.


-- 
Wes Groleau

   “Grant me the serenity to accept those I cannot change;
    the courage to change the one I can;
    and the wisdom to know it's me.”
                                — unknown

[toc] | [prev] | [next] | [standalone]


#748

FromDaveC <invalid@invalid.net>
Date2012-03-25 11:13 -0700
Message-ID<0001HW.CB94AE5700D511FEB02919BF@news.eternal-september.org>
In reply to#746
> Curious, why do you want to bypass them for some addresses?  Do they do 
> things you DON'T want?

Things are slowed down somewhat when using the service. And my bandwidth with 
their service will be less if I'm sending mail and other (non-BBC) 
non-VPN-necessary requests through the tunnel, which leaves less for the 
video stream (the reason for the subscription).

When I inquire at a web site about some product, I'm always shown prices in 
GBP not USD. I have to turn off the VPN and try again. If I'm streaming a 
video, I will lose some of that show (it's not archived).

Not crucial stuff, but annoying. If I'm paying for a service, I want to be 
able to customize it to my liking.

d.

[toc] | [prev] | [next] | [standalone]


#750

FromWarren Oates <warren.oates@gmail.com>
Date2012-03-25 17:39 -0400
Message-ID<4f6f90a6$0$32079$c3e8da3$40d4fd75@news.astraweb.com>
In reply to#748
In article 
<0001HW.CB94AE5700D511FEB02919BF@news.eternal-september.org>,
 DaveC <invalid@invalid.net> wrote:

> When I inquire at a web site about some product, I'm always shown prices in 
> GBP not USD. I have to turn off the VPN and try again. If I'm streaming a 
> video, I will lose some of that show (it's not archived).

It's funny, sometimes, if you visit a site using the VPN, it sets 
cookies. I was getting adverts in sterl(ahem) in GBP on my Facebook page 
after I'd switched the VPN off. Then I found I could switch the adverts 
off.

> 
> Not crucial stuff, but annoying. If I'm paying for a service, I want to be 
> able to customize it to my liking.

I agree. You should contact Witopia's service people.
-- 

... do not cover a warm kettle or your stock may sour. -- Julia Child

[toc] | [prev] | [next] | [standalone]


#755

FromDaveC <invalid@invalid.net>
Date2012-03-25 21:11 -0700
Message-ID<0001HW.CB953A6600F5E5C7B02919BF@news.eternal-september.org>
In reply to#750
>> Not crucial stuff, but annoying. If I'm paying for a service, I want to be 
>> able to customize it to my liking.

> I agree. You should contact Witopia's service people.

Witopia support says that in future updates "we may allow you to choose 
certain services or websites to not be protected by the VPN if you prefer. 
But for the now you cannot." 

It sounds great, but a long time ago I learned to not make plans on 
"futureware".

I think I'll go back to Safari & configure automatic proxy configuration via 
a .pac file. That works for all beeb archived iPlayer content but not, for 
some reason, the live streams. 

(I wonder why the live stream works with Witopia's product but not when 
viewed via another proxy...)

[toc] | [prev] | [next] | [standalone]


#756

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-03-26 00:40 -0400
Message-ID<jkorvv$fr6$1@dont-email.me>
In reply to#755
On 03-26-2012 00:11, DaveC wrote:
> (I wonder why the live stream works with Witopia's product but not when
> viewed via another proxy...)

The live stream link probably includes a different port that
your proxy.pac didn't allow for.

-- 
Wes Groleau

A pessimist says the glass is half empty.
An optimist says the glass is half full.
An engineer says somebody made the glass
        twice as big as it needed to be.

[toc] | [prev] | [next] | [standalone]


#757

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-03-26 01:08 -0400
Message-ID<4f6ff9e8$0$3990$c3e8da3$b23f186d@news.astraweb.com>
In reply to#756
I'll repeat my original anwer with  few more details.

netstat -r to list current routes

the "route" command can be used to manually add a static route. This
does not survive a reboot so it need sto be done whenever you reboot.

route add -host <ip address of google>/32  <ip address of your router>

If you knwo that google has a whole block fo IPs in your country, then
you can use -net instead of -host and specify a smaller mask such as /24
or /20 of whatever.

Remember that when you try to access google, you are directed to one of
many of their IP addresses. You want to catch as many as possible for
your route.


man netstat and man route gets you help, so does Mr Google with "static
route OS-X"

There are also examples on how to set i up so the route is added when
you boot.

When you setup a VPN, it basically changes you default route to point to
the VPN interface. If you have routes defived for netwblocks, those
routes kicks in before the VPN.




[toc] | [prev] | [next] | [standalone]


#758

FromDaveC <invalid@invalid.net>
Date2012-03-25 23:16 -0700
Message-ID<0001HW.CB9557DD00FCCDB1B02919BF@news.eternal-september.org>
In reply to#757
> Remember that when you try to access google, you are directed to one of
> many of their IP addresses. You want to catch as many as possible for
> your route.
...
[JF Mezei]

I'm confused. Why the references to Google? If you are trying to help me 
access Google, that's just one example I used. 

I want to have *every* web site I want to go to (ie, I want the default 
action to be) to not use the VPN. In other words, of the millions of web 
sites I'll visit in the future, only those with "www.bbc.co.uk" do I want to 
go through the VPN. *All* others I want to access directly.

Hope that helps clarify my needs.

Thanks,
Dave

[toc] | [prev] | [next] | [standalone]


#759

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-03-26 07:19 +0000
Message-ID<slrnjn05t4.sf9.gsm@cable.mendelson.com>
In reply to#758
DaveC wrote:

> I want to have *every* web site I want to go to (ie, I want the default 
> action to be) to not use the VPN. In other words, of the millions of web 
> sites I'll visit in the future, only those with "www.bbc.co.uk" do I want to 
> go through the VPN. *All* others I want to access directly.

Actually you don't. You want all connections to servers used by the BBC
to go through the VPN, no matter what their DNS names resolve to.

That's a very different thing. 

Geoff.


-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM
My high blood pressure medicine reduces my midichlorian count. :-(

[toc] | [prev] | [next] | [standalone]


#761

FromPaul Sture <paul@sture.ch>
Date2012-03-26 10:55 +0200
Message-ID<qhn549-an1.ln1@news.sture.ch>
In reply to#759
On Mon, 26 Mar 2012 07:19:04 +0000, Geoffrey S. Mendelson wrote:

> DaveC wrote:
> 
>> I want to have *every* web site I want to go to (ie, I want the default
>> action to be) to not use the VPN. In other words, of the millions of
>> web sites I'll visit in the future, only those with "www.bbc.co.uk" do
>> I want to go through the VPN. *All* others I want to access directly.
> 
> Actually you don't. You want all connections to servers used by the BBC
> to go through the VPN, no matter what their DNS names resolve to.
> 
> That's a very different thing.
> 

Yes. For example when I listen to BBC radio over the internet I need to 
enable Javascript for these three:

bbc.co.uk
radioplayer.co.uk
bbcimg.co.uk

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#766

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-03-26 16:10 -0400
Message-ID<4f70cd2b$0$2240$c3e8da3$76a7c58f@news.astraweb.com>
In reply to#758
DaveC wrote:

> I want to have *every* web site I want to go to (ie, I want the default 
> action to be) to not use the VPN. In other words, of the millions of web 
> sites I'll visit in the future, only those with "www.bbc.co.uk" do I want to 
> go through the VPN. *All* others I want to access directly.


Same principle, but you'll need to do this manually.

Setup the VPN. This will set the default route to go through the VPN.

In the System Preferences, network,  you will see that your VPN
interface is at the top. There is a way to move it down to change
precedence.  (click on the cogged wheel below the list of interfaces,
and "set service order".)

You want your standard ethernet interface to be above that of the VPN.

Then you check your routes. You want to make sure yoru default route
(0.0.0.0 )  goes to your router

 netstat -r -n
Routing tables

Internet:
Destination        Gateway            Flags        Refs      Use   Netif
Expire
default            10.0.0.1           UGSc          148        0     en0

you can use the route command to ensure that your default route goes to
the IP address of your router via the en0 interface .

At this stage, you VPN interface won't be used for much.

You can then add routes (with the "route add"  command) to point the BBC
IP addresses to the VPN interface and/or gateway address.


This way, when the operating system gets a request to connect to a BBC
IP address it will route it via the VPN interface. When it gets other
requests, it goes via the default route to your router and bypasses the VPN.

[toc] | [prev] | [next] | [standalone]


#769

FromDaveC <invalid@invalid.net>
Date2012-03-26 22:18 -0700
Message-ID<0001HW.CB969BCE0148BAADB02919BF@news.eternal-september.org>
In reply to#766
Thanks for your interest.

> You can then add routes (with the "route add"  command) to point the BBC
> IP addresses to the VPN interface and/or gateway address.

This is the fly in the ointment. I am looking for a way to specify "*.co.uk*" 
as the domain to be routed to the VPN interface, but it looks like this is 
not possible; it must be numeric IPs. I don't know (and it's probably a huge 
quantity of them) all the IP addresses BBC uses for streaming. 

Maybe I can specify a range of IP's and just specify all allocated to the 
U.K.?

Dave

[toc] | [prev] | [next] | [standalone]


#770

From"Geoffrey S. Mendelson" <gsm@mendelson.com>
Date2012-03-27 07:09 +0000
Message-ID<slrnjn2pob.58k.gsm@cable.mendelson.com>
In reply to#769
DaveC wrote:
>
> Maybe I can specify a range of IP's and just specify all allocated to the 
> U.K.?

I think I said that in a previous post. If I did not, I had intended to 
and appologize for not doing so.

When I googled it, I found a lot of people asking the same question, with
no real answer. I can be done, the list of IP address ranges and where they
are is public and available on line, and maybe someone did post a list by
country. 

That may have been why I did not answer.........

The geolocating companies have an opposite list, they can search by IP and
give you country. 

BBc.com and BBC.co.uk resolve to a 212 address, so I would start with
212.0.0.0/24.

Geoff.

-- 
Geoffrey S. Mendelson,  N3OWJ/4X1GM
My high blood pressure medicine reduces my midichlorian count. :-(

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | comp.sys.mac.comm


csiph-web