AlwaysOn VPN - Posture check to disable route when local #1839

Open
opened 2025-11-20 06:07:46 -05:00 by saavagebueno · 3 comments
Owner

Originally created by @dp466 on GitHub (Apr 25, 2025).

im trying to install VPN on corporate computers and configure them so its always active but im trying to configure a Posture Check so the VPN isnt active while the computer is locally on the corporate network but that dont seem to be working

Image

when they are local and the VPN is "Connected" everything is slower and traffic still seem to be going trough the tunnel

is the posture check only verified at the conexion moment or is it always re-evaluated ?

thanks!

Originally created by @dp466 on GitHub (Apr 25, 2025). im trying to install VPN on corporate computers and configure them so its always active but im trying to configure a Posture Check so the VPN isnt active while the computer is locally on the corporate network but that dont seem to be working ![Image](https://github.com/user-attachments/assets/15871ac1-cf44-47b8-8264-df29c3c9aa36) when they are local and the VPN is "Connected" everything is slower and traffic still seem to be going trough the tunnel is the posture check only verified at the conexion moment or is it always re-evaluated ? thanks!
saavagebueno added the triage-needed label 2025-11-20 06:07:46 -05:00
Author
Owner

@davidchi2020 commented on GitHub (Apr 26, 2025):

I also encountered the same problem.
In the settings, I unchecked the specified network and restarted the OS to solve it.
It would be better if the program could automatically determine it.

@davidchi2020 commented on GitHub (Apr 26, 2025): I also encountered the same problem. In the settings, I unchecked the specified network and restarted the OS to solve it. It would be better if the program could automatically determine it.
Author
Owner

@dp466 commented on GitHub (Apr 28, 2025):

I also encountered the same problem. In the settings, I unchecked the specified network and restarted the OS to solve it. It would be better if the program could automatically determine it.

i know it can be done manually.. but im trying to do it automatically so the users that are not tech savy dont have to go play there

@dp466 commented on GitHub (Apr 28, 2025): > I also encountered the same problem. In the settings, I unchecked the specified network and restarted the OS to solve it. It would be better if the program could automatically determine it. i know it can be done manually.. but im trying to do it automatically so the users that are not tech savy dont have to go play there
Author
Owner

@volkermauel commented on GitHub (Jun 6, 2025):

adding a check for the network name that is being sent out by dhcp would be a nice feature i guess.

this way, if i get the networkname homelab.tld i can disable the tunneling, as i am already somewhere where it's safe

@volkermauel commented on GitHub (Jun 6, 2025): adding a check for the network name that is being sent out by dhcp would be a nice feature i guess. this way, if i get the networkname homelab.tld i can disable the tunneling, as i am already somewhere where it's safe
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#1839