Goal
Dedicated Netgear R6220 VPN router:
Router → WAN (ISP)
LAN/WiFi → NordVPN WireGuard
VPN down → LAN/WiFi blocked (kill switch)
1. Reference configuration
| Setting | Value |
|---|---|
| WAN gateway | 10.33.1.1 |
| LAN IP | 10.81.1.1 |
| LAN subnet | 10.81.1.0/24 |
| WireGuard interface | wireguard |
| VPN server | jp649.nordvpn.com (Osaka) |
| Endpoint | 192.166.247.134:51820 |
| Nord DNS | 103.86.96.100, 103.86.99.100 |
| PBR | 1.2.2-r14 |
2. Backup before changes
sysupgrade -b /tmp/openwrt-backup.tar.gz
Download the backup before proceeding. Keep an SSH session open over LAN.
3. Configure routing
uci set network.wan.defaultroute='1'
uci set network.@wireguard_wireguard[0].route_allowed_ips='0'
uci commit network
service network reload
Expected router default route:
ip route
# default via 10.33.1.1 dev wan
WireGuard peer must retain:
Allowed IPs: 0.0.0.0/0
Persistent Keepalive: 25
4. Configure PBR
Install if necessary:
apk update
apk add pbr luci-app-pbr
In Services → Policy Based Routing, enable strict enforcement and create two policies:
| Field | LAN via VPN | Nord DNS via VPN |
|---|---|---|
| Enabled | Yes | Yes |
| Local addresses | 10.81.1.0/24 | Empty |
| Remote addresses | Empty | 103.86.96.100, 103.86.99.100 |
| Interface | wireguard | wireguard |
| Chain | prerouting | output |
| Protocol | all | all |
Restart:
service pbr enable
service pbr restart
service pbr status
Both policies must report success.
Important: With PBR 1.2.2, src_addr and dest_addr are UCI lists. Use uci add_list, not a space-separated string with uci set.
5. Configure DNS
Windows clients should receive 10.81.1.1 as their DNS server.
uci set dhcp.@dnsmasq[0].noresolv='1'
uci -q delete dhcp.@dnsmasq[0].server
uci add_list dhcp.@dnsmasq[0].server='103.86.96.100'
uci add_list dhcp.@dnsmasq[0].server='103.86.99.100'
uci -q delete dhcp.lan.dhcp_option
uci add_list dhcp.lan.dhcp_option='6,10.81.1.1'
uci commit dhcp
service dnsmasq restart
The Nord DNS PBR output policy is essential: dnsmasq runs on the router, which otherwise uses WAN.
6. Disable client IPv6
uci set network.lan.ip6assign='0'
uci set network.wan6.disabled='1'
uci set dhcp.lan.ra='disabled'
uci set dhcp.lan.dhcpv6='disabled'
uci set dhcp.lan.ndp='disabled'
uci commit network
uci commit dhcp
service network reload
service odhcpd restart
These settings disable LAN IPv6 services, not necessarily all IPv6 traffic. Verify separately.
7. Firewall / kill switch
Verify under Network → Firewall:
- LAN → WireGuard forwarding allowed
- LAN → WAN forwarding not allowed
- WireGuard zone masquerading enabled
- PBR strict enforcement enabled
Optional: redirect LAN TCP/UDP port 53 to 10.81.1.1:53 to intercept manually configured conventional DNS servers.
DNS-over-HTTPS and DNS-over-TLS require additional controls.
8. Verification checklist
- [ ]
wg showreports a recent handshake - [ ]
ip routeshows WAN as router default - [ ]
service pbr statusshows both policies successfully installed - [ ] Router public IP = ISP
- [ ] Wi-Fi client public IP = NordVPN Osaka
- [ ] Windows DNS server = 10.81.1.1
- [ ] DNS leak test shows no ISP resolvers
- [ ] No unintended IPv6 connectivity
- [ ] VPN down → clients lose Internet, router retains Internet
Useful diagnostics:
wg show
ip route
service pbr status
uci show pbr
logread | grep -i pbr
tcpdump -ni wireguard 'port 53'
Note: ip route get without PBR marks does not prove that DNS uses WireGuard.
9. Common failures
| Symptom | Likely cause |
|---|---|
| VPN handshake, no client Internet | Missing LAN PBR rule, firewall or NAT issue |
| Clients use ISP public IP | LAN PBR policy disabled or wrong subnet |
| Correct VPN IP, ISP DNS leak | dnsmasq queries routed over WAN |
| PBR says no source/destination parameters | Invalid or empty policy |
| Duplicate Nord DNS policies | Leftovers from previous scripts |
| Router loses Internet when VPN fails | WireGuard still installed as main default route |
| IPv6 leak | IPv6 still active outside the tunnel |
Cleanup duplicate DNS policies
for s in $(uci show pbr |
sed -n "/\.name='Nord DNS via VPN'/s/\.name=.*//p"); do
uci delete "$s"
done
uci commit pbr
Recreate one valid Nord DNS policy, then restart PBR.