I don't think the vpn was stopped when I ran the command. If I uncheck 'Enabled' under open vpn and hit stop. The VPN connection still starts right back up.
I don't know what's the difference between gateway and interface in policy settings. Examples in README uses gateway. For me it doesn't work. Changing gateway to interface works.
The main issue with ipv6 is getting ipv6 vpn to work with the router in the first place. Most commercial vpns will give a single ipv6 address which cannot be used on the router unless you do NAT. Those commercial ipv6 ips are meant only to be used on the client directly. You need to send a separate /64 to the router which it can use for assigning ips to the clients. I have the ability to do this now since my server has a /48, but I don't know what config or changes will be needed at the server and the router. I would like to try this out, but I can't promise a timeline.
Restarting vpn-policy-routing clears ipsets. When client opens site which has policy (remote domain) it goes through default gateway. For me it looks like dnsmasq has IP address of domain in cache and does not add it to ipset (I checked vpn-policy-routing status). Restarting dnsmasq does not help. Rebooting router helps.
Should I use reload instead of restart? Is there any way to force dnsmasq to add IP addresses to ipset?
I'd suspect the client cache is the reason for this behaviour. AFAIK restarting dnsmasq clears its cache. If you find evidence to the contrary, please let me know. dnsmasq should start filling ipsets again on request from a client or when idle.
I'm having a really bad time trying to make my scenario working: an SSID (192.168.1.0/24) routed through WAN and another SSID (192.168.2.0/24) routed through an OpenVPN tun0.
The clients on the VPN SSID get the IP address, but there's no Internet available for them. Also, the tun0 interface has "RX: 0 B (0 Pkts.)", while the TX keeps on increasing.
My doubt is that is a firewall rule missing, but I'm not sure about it and I honestly don't know what else to do.
I post here my configuration, hoping that somebody could help me