Jump to content

Hi!

 

I'm not that well versed in the world of Networking, so i am writing for some guidance.

 

You are all probably sick of questions like this but please bear with me!

 

I did see LTT's Tailscale video

 

As we all know Netflix is removing the shared account feature, and i wanted to try to throw myself a little out into the vast and deep Networking water.

What i want to accomplish or even figure out if it is possible is: Can i set-up a VPN that split tunnels ONLY Netflix traffic?

 

I get that keeping track of every Netflix IP would be a hassle but if you could split tunnel domains? if that would work? or an app on AppleTV (Other streaming boxes are available)

 

or even if you just split tunnel a single browser through the VPN?

 

I'm pretty sure i can figure out the technical side of it with some google-fu but if the split tunneling is at all possible to do?

 

Thank you to any Networking gods that responds!

System Administrator

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/
Share on other sites

Link to post
Share on other sites

On 5/30/2023 at 1:31 PM, Zicco2 said:

Hi!

 

I'm not that well versed in the world of Networking, so i am writing for some guidance.

 

You are all probably sick of questions like this but please bear with me!

 

I did see LTT's Tailscale video

 

As we all know Netflix is removing the shared account feature, and i wanted to try to throw myself a little out into the vast and deep Networking water.

What i want to accomplish or even figure out if it is possible is: Can i set-up a VPN that split tunnels ONLY Netflix traffic?

 

I get that keeping track of every Netflix IP would be a hassle but if you could split tunnel domains? if that would work? or an app on AppleTV (Other streaming boxes are available)

 

or even if you just split tunnel a single browser through the VPN?

 

I'm pretty sure i can figure out the technical side of it with some google-fu but if the split tunneling is at all possible to do?

 

Thank you to any Networking gods that responds!

I run a pfsense firewall and I’m sure I could make this work via that, but don’t know how as I never have. What I do for a single device (smart TV), is I route it out over a VPN to another network I own in a physically different location. So all traffic to that TV routes over the VPN. Similar idea, but more broad; I am not doing specific traffic/IP/domain filtering, I just have an internal IP address (the TV) go out over the VPN. This is very easy to set up, and for my needs works perfectly. 

Rig: i7 13700k +Contact Frame - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Crucial P3 2TB NVMe for photo work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - PTM 7950 - - XT45 X-Flow 420 + UT60 280 rads externally mounted - - EK XRES RGB PWM - - Fractal Define S2 - - DellAlienware AW3423DWF 34" -- Logitech Pro X Superlight - - Logitech G710+ - - LTT Northern Lights Deskpad

 

Headphones/amp/dac: Schiit Bifrost Multibit - -  Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x8TB WD Red RAID Z2 - - 2x 800 GB SAS SSD’s (1 SLOG, 1 L2Arc) - - 45 HomeLab HL15 15 Drive 4U - - Corsair RM650i - - LSI 9305-16i HBA - - TreuNAS + many other VM’s

 

Unifi UDM Pro in front of full unifi network infrastructure

 

iPhone 17 Pro - - MacBook Air M3

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15965782
Share on other sites

Link to post
Share on other sites

10 hours ago, Block0 said:

palo alto firewalls could do it with SSL vpns or you could use routing for those tunnels, but that's way more effort than its worth

Im guessing Palo Alto Firewalls are not cheap? a quick google search indicates they are for enterprise businesses, or do they have "smaller" ones with the same functionality?

System Administrator

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15966357
Share on other sites

Link to post
Share on other sites

10 hours ago, LIGISTX said:

I run a pfsense firewall and I’m sure I could make this work via that, but don’t know how as I never have. What I do for a single device (smart TV), is I route it out over a VPN to another network I own in a physically different location. So all traffic to that TV routes over the VPN. Similar idea, but more broad; I am not doing specific traffic/IP/domain filtering, I just have an internal IP address (the TV) go out over the VPN. This is very easy to set up, and for my needs works perfectly. 

Split tunneling a device would work as well, but having it work just the Netflix part would be preferable.

System Administrator

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15966359
Share on other sites

Link to post
Share on other sites

5 minutes ago, Zicco2 said:

Split tunneling a device would work as well, but having it work just the Netflix part would be preferable.

That isn’t really split tunneling. Split tunneling is what you want to do, not what I am doing and saying you can rather easily do. Split tunneling is when you route specific traffic over different gateways in this instance. What I suggest is just routing 100% of a devices traffic over a different gateway. You can always purchase a rather cheap streaming device that supports Netflix, route 100% of its traffic over the VPN gateway, and use it solely for Netflix for example. Lots of ways to skin this cat. 

 

Having a device go out over a VPN is very simple in pfsense, but trying to get a device to route only specific traffic is more difficult since I am not sure you can easily know all of the external connections Netflix will try to make. If you miss any, I assume it’ll be not happy.

Rig: i7 13700k +Contact Frame - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Crucial P3 2TB NVMe for photo work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - PTM 7950 - - XT45 X-Flow 420 + UT60 280 rads externally mounted - - EK XRES RGB PWM - - Fractal Define S2 - - DellAlienware AW3423DWF 34" -- Logitech Pro X Superlight - - Logitech G710+ - - LTT Northern Lights Deskpad

 

Headphones/amp/dac: Schiit Bifrost Multibit - -  Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x8TB WD Red RAID Z2 - - 2x 800 GB SAS SSD’s (1 SLOG, 1 L2Arc) - - 45 HomeLab HL15 15 Drive 4U - - Corsair RM650i - - LSI 9305-16i HBA - - TreuNAS + many other VM’s

 

Unifi UDM Pro in front of full unifi network infrastructure

 

iPhone 17 Pro - - MacBook Air M3

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15966376
Share on other sites

Link to post
Share on other sites

17 hours ago, LIGISTX said:

I run a pfsense firewall and I’m sure I could make this work via that, but don’t know how as I never have. What I do for a single device (smart TV), is I route it out over a VPN to another network I own in a physically different location. So all traffic to that TV routes over the VPN. Similar idea, but more broad; I am not doing specific traffic/IP/domain filtering, I just have an internal IP address (the TV) go out over the VPN. This is very easy to set up, and for my needs works perfectly. 

It can be done with pfsense as I have my own VPN tunnel and a VPN client. The VPN tunnel is used to connect to my network from outside, as for the VPN client is used to connect VPN services like PIA or NordVPN.

 

7 hours ago, Zicco2 said:

Split tunneling a device would work as well, but having it work just the Netflix part would be preferable.

If you are able to setup a Pfsense with a VPN tunnel/VPN client you will be able to separate devices using aliases. So with my network, I have multiple VLANs which I manage.

 

VLANs which I have:

  1. IT LAN - Can access all networks - 10.1.20.X
  2. Servers - Server VLAN - 10.1.70.X can only communicate with IT LAN
  3. IOT - for smart devices - 10.1.21.X - internet access only
  4. Home & Guest - for home and for guest access- Internet access only

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15966742
Share on other sites

Link to post
Share on other sites

53 minutes ago, Sir Asvald said:

It can be done with pfsense as I have my own VPN tunnel and a VPN client. The VPN tunnel is used to connect to my network from outside, as for the VPN client is used to connect VPN services like PIA or NordVPN.

 

If you are able to setup a Pfsense with a VPN tunnel/VPN client you will be able to separate devices using aliases. So with my network, I have multiple VLANs which I manage.

 

VLANs which I have:

  1. IT LAN - Can access all networks - 10.1.20.X
  2. Servers - Server VLAN - 10.1.70.X can only communicate with IT LAN
  3. IOT - for smart devices - 10.1.21.X - internet access only
  4. Home & Guest - for home and for guest access- Internet access only

Yes, I agree with all of this and I have a similar setup. But as far as ONLY routing Netflix traffic over the VPN which was the original question, that’s what I am saying is a more difficult task.

Rig: i7 13700k +Contact Frame - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Crucial P3 2TB NVMe for photo work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - PTM 7950 - - XT45 X-Flow 420 + UT60 280 rads externally mounted - - EK XRES RGB PWM - - Fractal Define S2 - - DellAlienware AW3423DWF 34" -- Logitech Pro X Superlight - - Logitech G710+ - - LTT Northern Lights Deskpad

 

Headphones/amp/dac: Schiit Bifrost Multibit - -  Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x8TB WD Red RAID Z2 - - 2x 800 GB SAS SSD’s (1 SLOG, 1 L2Arc) - - 45 HomeLab HL15 15 Drive 4U - - Corsair RM650i - - LSI 9305-16i HBA - - TreuNAS + many other VM’s

 

Unifi UDM Pro in front of full unifi network infrastructure

 

iPhone 17 Pro - - MacBook Air M3

Link to comment
https://linustechtips.com/topic/1510164-private-vpn-guidance/#findComment-15966821
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×