Doc status: current as of v2.8.6 · 2026-08-28
This guide has moved. Every section below now lives in
REAPER-GUIDE.md, the single Reaper manual, under 4.4 Policy Routing. It is the same material, kept current in one place instead of two.This file remains so that the ? buttons on the Policy Routing page of already-installed routers keep working. Each heading below preserves its original link target and points at the new location. Nothing here is maintained — follow the link.
Jump straight to the full section: REAPER-GUIDE.md § 4.4
Policy Routing in brief, so this page is not useless on its own: it decides which traffic uses which path — an OpenVPN or WireGuard client, the plain WAN, or nowhere — by a rule you write. It is the piece VPN Director was missing, because it can match a named object or domain list or a device, not only an address. A Policy Routing rule wins over a VPN Director rule for the same traffic. A rule targeting a VPN client is fail-closed: if the tunnel drops the traffic is blocked, never leaked to the WAN. It is off by default, and turning it on changes nothing until you add a rule.
Moved → 4.4.1 How it works
Moved → 4.4.2 The page
Moved → 4.4.3 What a rule matches
Moved → 4.4.4 Domain lists
Moved → 4.4.5 Where a rule sends traffic
Moved → 4.4.6 Order and precedence
Moved → 4.4.7 Fail-closed
Moved → 4.4.8 Examples
Moved → 4.4.9 Limits and gotchas
Maintainers: do not add content here. This file exists only to keep the deep links in shipped
firmware resolving. When a firmware release ships whose ? buttons point directly at
REAPER-GUIDE.md, and enough time has passed that older images are out of circulation, this file
can be deleted.