No internet or home network access on Wireguard VPN Server on AX72 Pro v1

No internet or home network access on Wireguard VPN Server on AX72 Pro v1

No internet or home network access on Wireguard VPN Server on AX72 Pro v1
No internet or home network access on Wireguard VPN Server on AX72 Pro v1
Sunday - last edited Monday
Model: Archer AX72 Pro  
Hardware Version: V1
Firmware Version: Archer AX72 Pro(EU)_V1_1.3.1 Build 20240426

I've been trying to set up a Wireguard VPN Server on Archer AX72 Pro router with no success on being able to access my local network or internet, even though it is saying in the log that I am connected (that's something, I guess!). 

 

I set up the Wireguard VPN Server using the following settings..

 

Tunnel IP Address: 10.5.0.1/32

Listen Port: 51820

Client Access: Internet and Home Network

DNS: Enabled

Persistent Keepalive: 25

Public Key: *****

Private Key: *****

 

For the account list...

 

Username: Test

Address: 10.5.0.3/32

Allowed clients: 0.0.0.0/1,128.0.0.0/1 (I've tried 0.0.0.0/0 that is mentioned on various help posts in other places but if I used this, it won't connect at all)

Allowed IPs: 10.5.0.3/32

 

I'm using Wireguard app on iPhone XR.  Although the log is saying connected, I can neither access the internet or my home network when I connect.

 

I've tried various configurations for IP addresses including following the guidance here (https://www.tp-link.com/us/support/faq/3772/) for the Wireguard setup for AX55.

 

I have a DDNS working.  When I go into the log on my iPhone XR I can see the name of the DDNS URL or my external IP address. 

 

My lan IP address is 192.168.1.*

 

I've not made any changes to any other setting in router, primarily because the guidance I've seen makes no mention of doing so, for example, Port Forwarding.

 

I've been trying to configure this now for several hours and just hit a brick wall.

 

Anybody offer any ideas or help?  

 

 

  0      
  0      
#1
Options
4 Reply
Re:No internet or home network access on Wireguard VPN Server on AX72 Pro v1
Sunday

  @GreyBear 

 

Hi,

 

Can you maybe post the part of the log that says "connected", including a few lines leading up to it?

 

It should definitely work with "Allowed IPs (Client): 0.0.0.0/0". (this value should already be populated by default on TP-Link's routers)
 

  0  
  0  
#2
Options
Re:No internet or home network access on Wireguard VPN Server on AX72 Pro v1
Sunday

@woozle 

 

Here you go....seems to go thru' an awful lot of 'stuff' until it gets to the final 'connected' at the end...

 

 

 

 

This is what happens when I change it to 0.0.0.0/0

 

 

 

 

 

 

  0  
  0  
#3
Options
Re:No internet or home network access on Wireguard VPN Server on AX72 Pro v1
Sunday

  @GreyBear 

 

I am not sure how to interpret the first screenshot, but the second screenshot indicates that the WireGuard client is not able to reach the WireGuard server on your AX72 Pro. 
Have you verified that your Internet connection is being assigned a public IPv4 address? In recent years that has been a stumbling block for quite many users.

 

Regarding the first screenshot. I have only Android devices to test with, but when I establish a connection then I get a bunch of "Routine: encryption worker X - started" messages and only when I disconnect then I get "Routine: encryption worker X - stopped" messages.
Having "Routine: encryption worker X - stopped" messages followed directly by a "Tunnel status is now 'connected'" message makes no sense to me.
 

  0  
  0  
#4
Options
Re:No internet or home network access on Wireguard VPN Server on AX72 Pro v1
Monday

@GreyBear 

 

If your iPhone XR fails to connect to the WireGuard VPN server, please check the following:

1. Set the allowed IPs to 0.0.0.0/0 on the AX72 Pro.
2. Attempt to reconnect multiple times on your iPhone XR until you see a line saying 'received' under the peer section, which indicates a successful connection.

 

This would be an issue with the iPhone, you could try connecting to the VPN server on another device, such as an Android or Windows.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer AX90 New Firmware Added Support for EasyMesh and Ethernet Backhaul If you found a post or response helpful, please click Helpful (arrow pointing upward icon). If you are the author of a topic, remember to mark a helpful reply as the "Recommended Solution" (star icon) so that others can benefit from it.
  0  
  0  
#5
Options