Setup WireGuard VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Setup WireGuard VPN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Setup WireGuard VPN
Setup WireGuard VPN
2024-02-18 13:46:50 - last edited 2024-02-24 18:07:22
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: Latest

Team,

 

See also attached image:

I'm strugling with seting up a WireGuard VPN where all traffic from vlan 225 should be using the VPN and the Ubuntu VPS to reach the Internet. Meaning clients and applications used in this vlan should believe that their Internet IP is X.Y.Z.77.

 

All other traffic should be using IP A.B.C.125 to reach the internet.

 

However until now, I can not get this working - all clients and applications in vlan 225 keep reporting A.B.C.125 as being their public Internet IP.

 

Anyone in a position to help me by explaining where to fill-in what IP adresses/subnets for the WireGuard config?

Ideally for both - the Omada ER605 router as well as the Ubuntu-VPS with WireGuard installed via apt get (i.e. whatever is in the default repository).

 

 

With warm regards - Will

 

=====

 

 

*** making it run like clockwork ***
  0      
  0      
#1
Options
3 Reply
Re:Setup WireGuard VPN
2024-02-19 01:39:36 - last edited 2024-02-24 18:07:22

Hi @ITV 

Thanks for posting in our business forum.

Allowed-IP set to 0.0.0.0/0 and this will route everything to the VPN tunnel. Which is what you need as proxy, to change the IP address from a.b.c.125 to x.y.z.77.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options
Re:Setup WireGuard VPN
2024-02-24 18:07:14 - last edited 2024-02-24 18:12:25

  @Clive_A 

 

An AllowpedIPs=0.0.0.0/0 means a full tunnel. Meaning all subnets/vlans will be routed through the tunnel.

I guess I need a split tunnel - meaning only one specific vlan/subnet needs be routed through the tunnel.

 

Ideally there would be 3 vlans/subnets - each with a different WG-tunnel - not sure if this is supported.

Meaning subnet/vlan A is routed through WG-tunnel-A, subnet/vlan B is routed through WG-tunnel-B and subnet/vlan C is routed through WG-tunnel-C.

The 3 tunnels are running against 3 different VPS-es each with their own, unique public-IP (where x.y.z.77 is one of these three).

 

All other traffic would/should bypass the WG-vpn and should use the direct-connected Internet connection with public IP a.b.c.125.

 

Any suggestion on how to make this work?

 

 

With warm regards - Will

 

 


 

*** making it run like clockwork ***
  0  
  0  
#3
Options
Re:Setup WireGuard VPN
2024-02-26 01:27:02

Hi @ITV 

Thanks for posting in our business forum.

Contradictory to what you described.

ITV wrote

I'm strugling with seting up a WireGuard VPN where all traffic from vlan 225 should be using the VPN and the Ubuntu VPS to reach the Internet. Meaning clients and applications used in this vlan should believe that their Internet IP is X.Y.Z.77.

 

Only when you set it to 0.0.0.0/0 can you do this highlighted part.

Or simply follow the guide I wrote for WG which explained you can just fill in allowed-ip with the VLAN subnet. That'll just allow you to access that VLAN you specified.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options