1
Votes

ER605 Wireguard VLAN and Interface Options

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
 
1
Votes

ER605 Wireguard VLAN and Interface Options

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER605 Wireguard VLAN and Interface Options
ER605 Wireguard VLAN and Interface Options
2023-11-12 18:08:14
Tags: #Wireguard VLAN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.2

With OpenVPN you can set a VLAN to use the VPN tunnel its not an all or nothing option (Client-to-Site option).

Wireguard needs to have the same type of option (Client-to-Site) and be able to send a single VLAN or multiple VLANs over the tunnel.

#1
Options
3 Reply
Re:ER605 Wireguard VLAN and Interface Options
2023-11-13 06:20:07

Hi @TechDad83 

Thanks for posting in our business forum.

What would be the proper parameter line in the WG official?

If I don't recall it wrong, there is nothing like what you said. WG does not support this itself. If you can point me in the right direction, that would be great.

 

About what you ask for, is this what you trying to say? Have an option to set this to define what VLAN interfaces can use the VPN tunnel?


 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
#2
Options
Re:ER605 Wireguard VLAN and Interface Options
2023-11-13 15:22:37

Hi @Clive_A 

Thank you for your response.

 

Lets say you have 3 VLANs

VLAN 6

VLAN 10

VLAN 99

 

I want VLAN 6 and 99 to go to the Internet normally.

VLAN 10 I want to tunnel through Wireguard tunnel.

 

In my case I have a VPN Provider (NORDVPN) I want to tunnel only a single VLAN over that tunnel. Currently I'm using OpenVPN Client to Site to do that. I have tried building routing tables, but that doesnt seem to do anything. Having an option to access the WG interface directly might help. The routing table sees it, just no way to say VLAN x to said interface.

#3
Options
Re:ER605 Wireguard VLAN and Interface Options
2023-11-14 01:33:24

Hi @TechDad83 

Thanks for posting in our business forum.

Current routing tables do not work with the VPN routing. So, expected behavior.

 

What would be the proper name for this feature in WG? I don't think I ever see this feature on WG. If there is no such a feature on WG, I am afraid that it might be hard for us to implement it because the WG is based on the WG official.

Or you mean the Policy Routing for the WG tunnel? This has been added to the request pool and pending for the further evaluation.

 

I think you should consider ACL instead. At least give it a try now. As a workaround.

After you configure the WG, three VLANs allow you to access the remote site, but you can use ACL which is effective universally. Try the GW ACL by LAN > WAN and use both SRC and DST as IP Group. And define the SRC as you desire (VLAN). DST to be the WG peer interface IP. That should block the access to the WG peer.

Or try the SW ACL if you have a switch. LAN - LAN ACL. Use SRC Network, DST IP Group(WG peer interface IP).

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
#4
Options