tomspark wrote:
Not dumb — blocking the NAS at the router level breaks VPN reconnection because the container can't reach your VPN provider to authenticate. If you want to isolate the NAS from the rest of your LAN (block it from accessing other devices), use a firewall rule instead: block the NAS's MAC from accessing other subnets, or put it on a separate VLAN. But don't block it from WAN/internet — the VPN tunnel needs outbound HTTPS to your provider's servers. What's your goal — keeping the NAS off the LAN for security, or something else? That'll tell me the right approach.
tomspark wrote:
The GLI-MT6000 doesn't expose firewall rules, so you're stuck with the client blocklist — which breaks VPN auth like you saw. Instead, put the NAS on a separate VLAN (if your router supports it) or just accept that blocking it at the router level isn't an option here. The good news: NordVPN + Wireguard through gluetun + the VPN kill switch in SparkBox already prevents leaks — if the tunnel drops, qBittorrent and Sonarr stop dead, nothing leaks. That's the real protection, not the router block. You're already good.
lexgrossman wrote:
Just didn't want any leaks from the media center apps, I'm using a GLI-MT6000 router with nordvpn wireguard setup and I was following your docs steps for blocking at the router level, and don't see any firewall rules available on my router only the port forwarding settings. My goal is to just not have any leaks from the torrents or anything, but still would like LAN access