Here’s the output after enp4s0 is disconnected and reconnected:
**#** journalctl -fu NetworkManager
-- Logs begin at Thu 2018-08-23 11:05:03 MST. --
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4519] dhcp4 (enp4s0): nameserver '192.168.1.1'
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4519] dhcp4 (enp4s0): state changed unknown -> bound
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4541] device (enp4s0): state change: ip-config -> ip-check (reason 'none', sys-iface-state: 'managed
')
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4550] device (enp4s0): state change: ip-check -> secondaries (reason 'none', sys-iface-state: 'manag
ed')
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4552] device (enp4s0): state change: secondaries -> activated (reason 'none', sys-iface-state: 'mana
ged')
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.4554] manager: NetworkManager state is now CONNECTED_LOCAL
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.5050] manager: NetworkManager state is now CONNECTED_SITE
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.5051] policy: set 'Home' (enp4s0) as default for IPv4 routing and DNS
Aug 23 11:13:51 linux-8chy NetworkManager[970]: <info> [1535048031.7155] device (enp4s0): Activation: successful, device activated.
Aug 23 11:13:52 linux-8chy NetworkManager[970]: <info> [1535048032.1028] manager: NetworkManager state is now CONNECTED_GLOBAL
**#** ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp4s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether bc:5f:f4:3a:8f:a2 brd ff:ff:ff:ff:ff:ff
inet 192.168.1.127/24 brd 192.168.1.255 scope global dynamic noprefixroute enp4s0
valid_lft 86388sec preferred_lft 86388sec
inet6 fe80::1994:faec:2088:8a3c/64 scope link noprefixroute
valid_lft forever preferred_lft forever
3: vmnet1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 1000
link/ether 00:50:56:c0:00:01 brd ff:ff:ff:ff:ff:ff
inet 172.16.106.1/24 brd 172.16.106.255 scope global vmnet1
valid_lft forever preferred_lft forever
inet6 fe80::250:56ff:fec0:1/64 scope link
valid_lft forever preferred_lft forever
4: vmnet8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 1000
link/ether 00:50:56:c0:00:08 brd ff:ff:ff:ff:ff:ff
inet 192.168.225.1/24 brd 192.168.225.255 scope global vmnet8
valid_lft forever preferred_lft forever
inet6 fe80::250:56ff:fec0:8/64 scope link
valid_lft forever preferred_lft forever
**#** ip r
default via 192.168.1.1 dev enp4s0 proto dhcp metric 100
172.16.106.0/24 dev vmnet1 proto kernel scope link src 172.16.106.1
192.168.1.0/24 dev enp4s0 proto kernel scope link src 192.168.1.127 metric 100
192.168.225.0/24 dev vmnet8 proto kernel scope link src 192.168.225.1
And lastly, after reconnecting to VPN, now behaving properly with ipfilter:
**#** journalctl -fu NetworkManager
-- Logs begin at Thu 2018-08-23 11:05:03 MST. --
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1722] keyfile: add connection in-memory (d14fd212-95ef-4b82-9958-65eded28f310,"tun0")
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1729] device (tun0): state change: unavailable -> disconnected (reason 'connection-assumed', sys-ifa
ce-state: 'external')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1745] device (tun0): Activation: starting connection 'tun0' (d14fd212-95ef-4b82-9958-65eded28f310)
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1847] device (tun0): state change: disconnected -> prepare (reason 'none', sys-iface-state: 'externa
l')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1854] device (tun0): state change: prepare -> config (reason 'none', sys-iface-state: 'external')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1862] device (tun0): state change: config -> ip-config (reason 'none', sys-iface-state: 'external')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1863] device (tun0): state change: ip-config -> ip-check (reason 'none', sys-iface-state: 'external'
)
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1867] device (tun0): state change: ip-check -> secondaries (reason 'none', sys-iface-state: 'externa
l')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.1869] device (tun0): state change: secondaries -> activated (reason 'none', sys-iface-state: 'extern
al')
Aug 23 11:16:09 linux-8chy NetworkManager[970]: <info> [1535048169.4327] device (tun0): Activation: successful, device activated.
**#** ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp4s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether bc:5f:f4:3a:8f:a2 brd ff:ff:ff:ff:ff:ff
inet 192.168.1.127/24 brd 192.168.1.255 scope global dynamic noprefixroute enp4s0
valid_lft 86243sec preferred_lft 86243sec
inet6 fe80::1994:faec:2088:8a3c/64 scope link noprefixroute
valid_lft forever preferred_lft forever
3: vmnet1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 1000
link/ether 00:50:56:c0:00:01 brd ff:ff:ff:ff:ff:ff
inet 172.16.106.1/24 brd 172.16.106.255 scope global vmnet1
valid_lft forever preferred_lft forever
inet6 fe80::250:56ff:fec0:1/64 scope link
valid_lft forever preferred_lft forever
4: vmnet8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 1000
link/ether 00:50:56:c0:00:08 brd ff:ff:ff:ff:ff:ff
inet 192.168.225.1/24 brd 192.168.225.255 scope global vmnet8
valid_lft forever preferred_lft forever
inet6 fe80::250:56ff:fec0:8/64 scope link
valid_lft forever preferred_lft forever
6: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 100
link/none
inet 10.66.10.6 peer 10.66.10.5/32 brd 10.66.10.6 scope global noprefixroute tun0
valid_lft forever preferred_lft forever
inet6 fe80::3bbc:710c:2ed8:af9a/64 scope link stable-privacy
valid_lft forever preferred_lft forever
**#** ip r
default via 10.66.10.5 dev tun0 proto static metric 50
default via 192.168.1.1 dev enp4s0 proto dhcp metric 100
10.66.10.1 via 10.66.10.5 dev tun0 proto static metric 50
10.66.10.5 dev tun0 proto kernel scope link src 10.66.10.6 metric 50
172.16.106.0/24 dev vmnet1 proto kernel scope link src 172.16.106.1
192.168.1.0/24 dev enp4s0 proto kernel scope link src 192.168.1.127 metric 100
192.168.1.1 dev enp4s0 proto static scope link metric 100
192.168.225.0/24 dev vmnet8 proto kernel scope link src 192.168.225.1
194.187.249.37 via 192.168.1.1 dev enp4s0 proto static metric 100
I don’t see anything obvious, but I also don’t know what to look for.