Wireguard intermittiant

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Wireguard intermittiant

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Wireguard intermittiant
Wireguard intermittiant
2023-04-06 22:07:05 - last edited 2023-04-07 22:07:01
Model: ER7206 (TL-ER7206)  
Hardware Version: V1
Firmware Version: 1.3.0

In conjunction with the controller version 5.9.31 I have been playing around with wireguard.

 

While I can get it to connect and pass some data it is somewhat intermittant, if I run a ping test to a mobile android device the pings are only about 25% successful. (the mobile is off WiFi on the cellular network) so connected via WAN.

 

From the mobile device I want to push all traffic down the tunnel and then route through the home internet connection, so 0.0.0.0/0 configured on the client, again it works sometimes.

 

From the client I cannot connect to any device in my internal networks, despite having the subnets they are in as allowed.

 

I'm a network engineer so familar with what I am doing and how things should be to route. I have no overlapping networks and everything reads as if it is configured correctly.

 

The routing table shows none of the networks configured for Wireguard which seems a little odd, but Wireguard I am not familiar with.

 

Is this still in its infancy wth TP Link with some of the usual beta test it in the wild bugs, has anyone else managed to get it to work properly and reliably.

 

I would expect if ACLs needed to be configured I would see an interface in the menus, I tried creating an IP group for the the wireguard subnet and opening that up as much as possible but made no difference.

 

Also need an export the settings function like OpenVPN to make setting the client up easier rather than copy pasting keys into files and sending them back and forth.

 

OpenVPN which I have setup works a treat.

  0      
  0      
#1
Options
5 Reply
Re:Wireguard intermittiant
2023-04-07 01:26:33

  @biomed32uk I tried for weeks to get Wireguard working, I'm pretty sure it's flat-out broken. I had to resort to throwing out my ER605 and returning to using OPNsense as my router and handling everything through it.


It feels like everything Omada-related is in perpetual beta at best. I have tons of features in my SDN that I can't use because none of the devices have been updated to support them, despite the fact, all those devices were purchased in the last 6 months. It makes no sense that these are sold as business products. I work for a very large software company and if we released our products like this, our customers would revolt.

  4  
  4  
#2
Options
Re:Wireguard intermittiant
2023-04-07 17:58:25

I agree, I am also convinced it does not work properly, think it's very early days yet and is not to be depended on yet.

 

The release of software / firmware does seem particularly disjointed where there are inter dependancies.

  1  
  1  
#3
Options
Re:Wireguard intermittiant
2023-04-08 08:46:40

jaymac1 wrote

  @biomed32uk I tried for weeks to get Wireguard working, I'm pretty sure it's flat-out broken. I had to resort to throwing out my ER605 and returning to using OPNsense as my router and handling everything through it.


It feels like everything Omada-related is in perpetual beta at best. I have tons of features in my SDN that I can't use because none of the devices have been updated to support them, despite the fact, all those devices were purchased in the last 6 months. It makes no sense that these are sold as business products. I work for a very large software company and if we released our products like this, our customers would revolt.

  @jaymac1   Ohh so true - we have resorted back to OPNsense, using OC200 to control switches & EAP's.  Future projects look like a switch back to OPNsense / Ubiquity UniFi kit.  At TP-Links rate of development it will be several years before the system is really usable

  2  
  2  
#4
Options
Re:Wireguard intermittiant
2023-04-10 03:54:58

Hello @biomed32uk

 

biomed32uk wrote

While I can get it to connect and pass some data it is somewhat intermittant, if I run a ping test to a mobile android device the pings are only about 25% successful. (the mobile is off WiFi on the cellular network) so connected via WAN.

 

May I know what IP address you tried to ping?

Could you share a screenshot of this?

 

biomed32uk wrote

From the mobile device I want to push all traffic down the tunnel and then route through the home internet connection, so 0.0.0.0/0 configured on the client, again it works sometimes.

From the client I cannot connect to any device in my internal networks, despite having the subnets they are in as allowed.

 

Could you provide more screenshots of VPN settings?

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#5
Options
Re:Wireguard intermittiant
2023-04-10 08:28:32

If I leave my android device on my local Wifi pings to its wireguard IP work absolutely fine

 

 

If I then disable the WiFi so it goes over to the cellular data the tunnel remains connected and shows the public IP in the dashboard, however the connection is then unreliable, I have tried this on two devices now - iOS and Android and they do the same. Seems as soon as WireGuard has to cross LAN to WAN in the router it breaks ?.

 

 

 

 

I'll draw out y network later on but don't think it is anything my side as such, I have tried various IP addresses for the wireguard tunnel, Class A, B and C with no difference made. Nothing is overlapping and should route.

 

best regards.

  0  
  0  
#6
Options