NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
miketheknight20
Oct 08, 2022Apprentice
Using Orbi In AP Mode
Hello - i have read and read that the only way to filter specific LAN IP's through a VPN service is to set-up the Orbi in AP mode, and connect the Orbi to a seperate router to handle the VPN connecti...
CrimpOn
Oct 20, 2022Guru - Experienced User
Yes, this can work. I, personally, hesitate to recommend such a complicated configuration.
First, you have to find a WiFi router that includes VPN Client capability. There are no Netgear routers that have this feature.
This creates two entirely separate WiFi networks (one for those special devices and one (the Orbi) for everything else.)
That means two separate WiFi routers to maintain.
If the Orbi is providing a wider area of coverage, how will this new router match that coverage?
Whatever is hard coded on that second router will be invisible to the Orbi router (hidden behind the second router NAT).
My guess is that the first solution offered is probably the most efficient:
- Choose a non WiFi router which is capable of designating that certain IP addresses are forced to use a VPN client (on that router)
- Place the Orbi in AP mode so that the primary router recognizes the MAC address of every device that asks for an IP address and is put into the correct "pool" of IPs.
The problem is that I have no idea what router is capable of this. I guarantee no Netgear router can. This is just a guess, but I doubt very much that any of the major consumer WiFi products will, either (eero, Google, Linksys, TP-Link......)
It appears that Ubiquiti routers have the ability to become a VPN Client:
What I do not see in any of the searches is how to force certain devices to use the VPN and other not to.
miketheknight20
Oct 21, 2022Apprentice
ohhh - let me read thro this article.
I was going to use the EdgeRouter to force the special devices thro VPN
- miketheknight20Oct 21, 2022Apprentice
AH - this seems more what I'm after https://help.ui.com/hc/en-us/articles/115015971688-EdgeRouter-OpenVPN-Server
now my question is - does it matter what IP range I use for the ERL devices? My ORBI is 192.168.5.XXX should I do 192.168.9.XXX for the ERL? I assume they have to be different to avoid conflicts?
Maybe this isn't what I'm after...this shows
The OpenVPN Server is the EdgeRouter - but why do i have to configure a client on the special devices? I don't want to have to set that up...