Direct at home, tunnel outside
This is the clearest expression of Orange. The same logical destination keeps the same name, but the transport changes automatically depending on where the user is.
# DNS: one suffix for everything at home. # At home, ask the router directly; away, ask the same router # through the tunnel — so the name resolves either way. [dns.rules] "*.home.lab" = [ { when = { src = "192.168.1.0/24" }, to = ["192.168.1.1"] }, { to = ["192.168.1.1"], via = "wg-home" }, ] "default" = { to = ["8.8.8.8", "1.1.1.1"] } # Routing: same name, two paths, chosen by where you are [[proxy.rules]] when = { domain = "*.home.lab", src = "192.168.1.0/24" } direct = true [[proxy.rules]] when = { domain = "*.home.lab" } to = "wg-home" # Other private targets stay direct. Last, so it never # shadows the two rules above. resolve_ip = false says # "don't look a hostname up just to reach me" — harmless # by default, and it saves queries if you ever switch # proxy.routing.resolve_for_ip_rules to "on_demand". [[proxy.rules]] when = { ip_cidr = "192.168.0.0/16" } resolve_ip = false direct = true