# Xbox, PlayStation and Nintendo Switch gateway

Use a dedicated LAN/VLAN/SSID on the Linux or OpenWrt gateway. Xbox One / Series
X|S, PS4 / PS5, Switch / Switch 2 use their normal Ethernet or Wi-Fi settings;
there is no native console VPN plugin in this package. Steam Deck may use the
same external gateway. Hardware acceptance for these consoles is pending.

## Existing gateway preset

`peervpnd.xbox-gateway.example.json` is the shared console preset despite its
historical filename. It uses `gateway_mode=router`, `gateway_lan_interface=br-lan`,
`gateway_lan_cidr=192.168.50.0/24`, and `gateway_dns_listen=192.168.50.1:53`.
Adapt the interface/subnet to a dedicated network before enabling it. Configure
the LAN address and DHCP server on the host/router first: this client does not
create a bridge, VLAN, wireless network or DHCP pool.

- Generic Linux: use the JSON preset, and advertise gateway/DNS `192.168.50.1`
  through the existing DHCP server. The built-in DNS listener owns port 53 on
  that LAN address; resolve conflicts with any other local resolver first.
- OpenWrt: use `/etc/config/lionvpn` and the procd service. Retain the default
  `gateway_dns_listen=127.0.0.1:1053`; dnsmasq serves LAN clients on TCP/UDP 53
  and forwards to the daemon. Use the dedicated LAN bridge and CIDR in UCI.
  Do not replace the generated OpenWrt daemon config with the Linux JSON preset.
- Every device on the selected interface/subnet follows this gateway policy.
  This version has no per-console policy selector. Keep other household
  devices on their existing network if they should not use the VPN.

## Console settings

| Device | Network setup | IP / DNS / proxy |
| --- | --- | --- |
| Xbox One / Series X\|S | Settings → General → Network settings | Automatic IP and DNS; connect to the dedicated LAN/SSID |
| PS4 / PS5 | Settings → Network → Set Up Internet Connection | Automatic IP/DNS, default MTU, no HTTP proxy |
| Switch / Switch 2 | System Settings → Internet → Internet Settings | Automatic IP/DNS, connect to the dedicated LAN/SSID |

Keep automatic IP/DNS when DHCP advertises the gateway correctly. For a manual
example, reserve an unused `192.168.50.x` address, mask `255.255.255.0`, gateway
`192.168.50.1`, DNS `192.168.50.1`. A DNS-only change does not route game traffic
through the VPN. Leave IPv6 disabled/blocked on this dedicated network until an
IPv6 VPN path is separately verified.

Run `lionvpn doctor`, connect, and check `lionvpn status`. Legacy UDP requires
an installed executable `peervpn-legacy`; LuCI disables it when absent. Legacy
TCP is unsupported. Choosing Legacy UDP is a transport choice and does not
alone prove all game UDP paths work. Inspect the bundled signed dependency
manifest for the actual components in the package.

## Acceptance checklist

Record the console, firmware, gateway package/firmware and VPN backend for each
run. Verify TCP/UDP DNS, sign-in, store download, matchmaking, multiplayer,
voice chat, idle recovery and sleep/wake. Repeat while disconnecting/reconnecting
the VPN and restarting the gateway; separately verify the configured fail-closed
behavior, WAN changes and IPv6 leakage. A successful web request is insufficient.

Record the console's NAT type and whether the WAN uses CGNAT/double NAT. Public
addresses, VPN server NAT and port mapping, upstream routers and the game
service all affect NAT type. This preset cannot guarantee Open NAT or Nintendo
NAT A/B. Do not enable UPnP, forwarding or a DMZ without a specific assessed need.

Official network setup references:
- https://www.playstation.com/en-us/support/connectivity/internet-connect-playstation/
- https://www.nintendo.com/sg/support/switch/internet/index.html
- https://support.xbox.com/help/hardware-network/connect-network/connect-console-to-home-network
