- 3 Posts
- 4 Comments
brownmustardminion@lemmy.mlOPto
Selfhosted@lemmy.world•Split Tunnel by Domain on Router Level?English
3·2 months agoThere’s a few apps I need to split out. Top priority is the signiant app which according to their documentation requires various AWS subdomains as well as their own. Specific subdomains are not specified and are implied to change regularly/on demand.
In an ideal world I would do my split tunneling on the device itself, but I don’t trust Windows and thus I run my VPN at the router level.
This isn’t a problem for most things, but I need to utilize my full bandwidth to transfer large files to clients in a timely manner, and a VPN becomes a massive bottleneck.
Pfsense lets you alias by domain name (I believe it regularly resolves down to an IP and uses that for filtering), but again, you need to supply the exact subdomain.
Just wondering if there’s an alternative solution to this issue. If it’s external to pfsense that’s not the end of the world.
Worst case scenario, I would set up a dedicated Linux box or maybe even a VM which could share access to the file transfer NAS and split tunnel the entire box around the VPN. Definitely less convenient.
brownmustardminion@lemmy.mlOPto
Selfhosted@lemmy.world•Selhosted Spotify Alternative for Closed Social Network?English
5·2 months agoThis looks promising. I’m going to investigate further. Thanks!
brownmustardminion@lemmy.mlto
World News@quokk.au•Suspect in Charlie Kirk murder captured after two-day manhunt
14·2 months agoEverybody with a liberal leaning is parroting this, yet the messages he left behind with the gun were antifascist slogans and there’s photos of him in costume for Halloween likely mocking trump. Sure there’s a chance he wrote it for the meme, but might as well hold off until the motive is clearer.
Meanwhile if you check out what conservatives are saying, it’s the same but polar opposite…“Antifa lefty confirmed. Typical…”. I swear everybody treats politics like a pro football league nowadays.

Your first suggestion is a clever one.
I can imagine writing a small script on the host machine to listen for subdomains, forward them to pfsense to update the aliases, and possibly set them to expire after a few days for security reasons.
Surely something like this exists. How to find it…?