I'm using a VPN on endpoint, but my Dream Router can still identify BitTorrent traffic....how?

…using NordVPN on *my endpoint.

The whole point of a VPN that is encrypts and obfuscates the traffic. How does the Dream Router know I have BitTorrent traffic? Or perhaps I forgot to have the VPN enabled on my “torrent” VM, but I really don’t think so…

For anyone feeling self righteous, I don’t torrent anything I shouldn’t. I just don’t want my ISP hassling me. If the router can see this, I assume my ISP can too.

Does your activity show up on https://iknowwhatyoudownload.com ? Or if you do a leak test here https://ipleak.net/ does it fail?

Are you binding Nord to qbit, and are you routing all traffic through Nord?

First thing I’d do is fire up the endpoint vpn and go to “what’s my ip and see what it says”. It has to be the vpn client is not on or configured wrong. I just went through this and created a vpn client connection openvpn on unifi directly with the vpn provider credentials. Then created a route pointing devices to that vpn interface . Endpoints don’t need the client on them this way. Note that Unifi will still be able to see the traffic as the dpi stats are pulled prior to the vpn route. This has been working great.

If the UDM is running the gateway to your commercial VPN provider, your network activity is only being encrypted between the UDM’s WAN port and the VPN server, meaning that the UDM itself is fully capable of analyzing the traffic, especially if the UDM is your local DNS resolver.

However if your commercial VPN is directly connected to your PC with DNS leak protection enabled, then I would think the IDS/IPS feature is enabled on your UDM and as far as I know it is possible to identify torrent traffic even when it is encrypted.

Wow, yes it knows! This is a great resource, thank you!

…I have to assume NordVPN either failed or I forgot to ensure it was on. I’m going to configure the VPN as an OpenVPN in my Dream Router so my entire network is protected.

I’m routing all traffic through NordVPN, yes. No split-tunnel.

I don’t use the qBitTorrent app often, mostly I use WebTorrent. I didn’t think there are any special settings in any torrent app I needed to be cautious of…?

I just went through this and created a vpn client connection openvpn on unifi directly with the vpn provider credentials. Then created a route pointing devices to that vpn interface . Endpoints don’t need the client on them this way.

This is what I should do, yes. Thank you!

My public IP shows as different on my torrent box from the public IP in the dream router on the WAN port, yes. Also when I go to speedtest(dot)net it shows “NordVPN” as my ISP.

Fantastic answer, thanks!