ok, thanksCompletely unnecessary to update them that often! Once every 3 months should be more than enough, maybe even once per year.
The MGT VLAN should only be used to access HTTP/S and SSH ports on the devices, each VLAN has an interface on the main router that serves DHCP, DNS etc.If you want to have all devices being controlled by the management VLAN then each device gets its IP from the managment vlan
I spent an hour reading this and still got nowhere. I know how VLANs work, I just dont know how to implement in routerOS.This topic taught me a lot about VLAN's on MikroTik devices:
It is, my issues are all on RouterOS7, verified in RouterOS7 Beta 3I thought chateau was only ros v7?
I tested the bug on beta3 and it’s still therewe have possible fix for this issue, that will be included in upcoming version.
On Device B?Does it make a difference if you lower the mtu size on wireguard interfaces?
It is not possible to use ordering sequence numbers in a script!
So how do I troubleshoot my failed installation then? It works if I put a cheap router in front and port forward, it fails when I put a $365 Mikrotik Chateau LTE12 in front and dstnat the WireGuard traffic.Exactly.
The 'broken port forwarding' theory. So no change for device B, but I also used 7.1beta2 on device A.
What exactly did you test??I didn't expect that it would change anything, but I tested device A with 7.1beta2 and no problem at all, everything works.
That was easy. :-)
ehmmmm I did not see that earlier. You are a gmail user (port 587, normal 25) so you should use inbound
Plain text / no encryption?Else go the SMTP/25 way.
CRL seems only be possible for certificates you generate on your Router.
I think that you also need this file:
The last two sets of packet captures where whilst connecting to Device B only. One WireGuard connection only.I'm running out of ideas. Last one for now, although there's no reason why it should be the problem, did you try to connect only to device B and no other server at the same time?
What routerOS version is running on the Mikrotik router doing your port forward?I tried quick test with RouterOS as WG server behind NAT with forwarded port, same as OP has, and it works fine. Exactly as expected, since WG shouldn't care about NAT at all.