Bypass VPN GlobalProxy for specific device on internal network and keep block non VPN traffic?

I have a GL-MT6000, latest firmware. I have a globalproxy vpn setup and have block non vpn traffic enabled incase the vpn drops.

Its working really well! All devices go via the VPN, if it drops, their internet dies too, its fabulous.

However, i notice my Nest thermostat refuses to work with the VPN up - i disable the vpn, Nest works just fine.

Is it possible at all to have just the Nest bypass all VPN etc? Does any one use the same setup with a Nest thermostat?

TIA

Admin Panel > VPN Dashboard > Global Proxy button. Switch to “Based on the client device” and then configure from there.

Thanks so much! I’ve been playing around for a day with-it and didn’t come across (or it didn’t register) - perfect, thankyou!

Can confirm this works, alas when “Block Non-VPN Traffic” is enabled, i cannot talk to the Nest. I use “Block Non-VPN Traffic” as a kill switch for all devices on the network - incase the VPN dies.

Any way to bypass “Block Non-VPN Traffic” and allow a select devices MAC? or another way to do this please?

Since the Nest probably needs to talk to many other devices on your LAN as well you unfortunately can’t use the normal method which would be to segment the VPN by VLAN and place the device on the guest VLAN.

For your particular use case, it would probably be best to assign the Nest a reserved IP and then develop a custom Firewall rule in LUCI (advanced settings > network > firewall) that allows access for that IP with a higher priority than the killswitch rules.

The other method would be to use the VLAN method I mentioned above, disable client isolation and write custom routes for local access between VLANs; but this seems more painful.

Any chance the Nest is able to connect to multiple Wi-Fi simultaneously?

Thanks, ill try the custom firewall rules, alas the Nest is very basic, one wifi connection, not even wired.