Goal

Dedicated Netgear R6220 VPN router:

Router   → WAN (ISP)
LAN/WiFi → NordVPN WireGuard
VPN down → LAN/WiFi blocked (kill switch)

1. Reference configuration

Setting Value
WAN gateway 10.33.1.1
LAN IP 10.81.1.1
LAN subnet 10.81.1.0/24
WireGuard interface wireguard
VPN server jp649.nordvpn.com (Osaka)
Endpoint 192.166.247.134:51820
Nord DNS 103.86.96.100, 103.86.99.100
PBR 1.2.2-r14

2. Backup before changes

sysupgrade -b /tmp/openwrt-backup.tar.gz

Download the backup before proceeding. Keep an SSH session open over LAN.

3. Configure routing

uci set network.wan.defaultroute='1'
uci set network.@wireguard_wireguard[0].route_allowed_ips='0'
uci commit network
service network reload

Expected router default route:

ip route
# default via 10.33.1.1 dev wan

WireGuard peer must retain:

Allowed IPs: 0.0.0.0/0
Persistent Keepalive: 25

4. Configure PBR

Install if necessary:

apk update
apk add pbr luci-app-pbr

In Services → Policy Based Routing, enable strict enforcement and create two policies:

Field LAN via VPN Nord DNS via VPN
Enabled Yes Yes
Local addresses 10.81.1.0/24 Empty
Remote addresses Empty 103.86.96.100, 103.86.99.100
Interface wireguard wireguard
Chain prerouting output
Protocol all all

Restart:

service pbr enable
service pbr restart
service pbr status

Both policies must report success.

Important: With PBR 1.2.2, src_addr and dest_addr are UCI lists. Use uci add_list, not a space-separated string with uci set.

5. Configure DNS

Windows clients should receive 10.81.1.1 as their DNS server.

uci set dhcp.@dnsmasq[0].noresolv='1'
uci -q delete dhcp.@dnsmasq[0].server
uci add_list dhcp.@dnsmasq[0].server='103.86.96.100'
uci add_list dhcp.@dnsmasq[0].server='103.86.99.100'

uci -q delete dhcp.lan.dhcp_option
uci add_list dhcp.lan.dhcp_option='6,10.81.1.1'

uci commit dhcp
service dnsmasq restart

The Nord DNS PBR output policy is essential: dnsmasq runs on the router, which otherwise uses WAN.

6. Disable client IPv6

uci set network.lan.ip6assign='0'
uci set network.wan6.disabled='1'
uci set dhcp.lan.ra='disabled'
uci set dhcp.lan.dhcpv6='disabled'
uci set dhcp.lan.ndp='disabled'

uci commit network
uci commit dhcp

service network reload
service odhcpd restart

These settings disable LAN IPv6 services, not necessarily all IPv6 traffic. Verify separately.

7. Firewall / kill switch

Verify under Network → Firewall:

  • LAN → WireGuard forwarding allowed
  • LAN → WAN forwarding not allowed
  • WireGuard zone masquerading enabled
  • PBR strict enforcement enabled

Optional: redirect LAN TCP/UDP port 53 to 10.81.1.1:53 to intercept manually configured conventional DNS servers.

DNS-over-HTTPS and DNS-over-TLS require additional controls.

8. Verification checklist

  • [ ] wg show reports a recent handshake
  • [ ] ip route shows WAN as router default
  • [ ] service pbr status shows both policies successfully installed
  • [ ] Router public IP = ISP
  • [ ] Wi-Fi client public IP = NordVPN Osaka
  • [ ] Windows DNS server = 10.81.1.1
  • [ ] DNS leak test shows no ISP resolvers
  • [ ] No unintended IPv6 connectivity
  • [ ] VPN down → clients lose Internet, router retains Internet

Useful diagnostics:

wg show
ip route
service pbr status
uci show pbr
logread | grep -i pbr
tcpdump -ni wireguard 'port 53'

Note: ip route get without PBR marks does not prove that DNS uses WireGuard.

9. Common failures

Symptom Likely cause
VPN handshake, no client Internet Missing LAN PBR rule, firewall or NAT issue
Clients use ISP public IP LAN PBR policy disabled or wrong subnet
Correct VPN IP, ISP DNS leak dnsmasq queries routed over WAN
PBR says no source/destination parameters Invalid or empty policy
Duplicate Nord DNS policies Leftovers from previous scripts
Router loses Internet when VPN fails WireGuard still installed as main default route
IPv6 leak IPv6 still active outside the tunnel

Cleanup duplicate DNS policies

for s in $(uci show pbr |
  sed -n "/\.name='Nord DNS via VPN'/s/\.name=.*//p"); do
  uci delete "$s"
done

uci commit pbr

Recreate one valid Nord DNS policy, then restart PBR.