I’m trying to create a Wireguard client on an hap ac2 which has to connect some clients of my 2nd house to the first one, while leaving the others on normal network. Some of them are Wireless and a couple wired.
I’ve managed to create wireguard peer and see traffic passing but I’m struggling trying to configure the next step:
A VLAN where to redirect all VPN Traffic
Assign 2 phisical port of the hap ac2 to that VLAN and a wireless SSID
Tag that VLAN on the main port (the hap ac2 is not the router in my case)
NAT all VLAN traffic to the VPN, which has a single address available for the client.
I’ve been trying since a week setting in different ways but no one of them is working. Sometimes I can see the devices in the vlan, they get an ip address from dhcp server I’ve configured but don’t make traffic, some other they never get the address but I can see they’re on the correct VLAN etc etc..
I’d be so glad if someone can point me in the right direction
For a virtual bottle of Wine, anything is possible!
Provide a network diagram showing what you are trying to accomplish as it is not clear.
Then provide both MT configs.
/export file=anynameyouwish (minus router serial number, public wanip information, keys etc.)
Again confused, if your debian home wg server is remote, then where are you located and what device do you have …
My last comment lost patience, as you refuse to be clear or provide a picture.
First of all, thank you for your patience, I understand that’s unclear.
Assume “Home 1” is where I live and “Home 2” is my gf’s house where I spend a lot of time. She has an awful ISP router, a Zyxel 8P Managed Switch and an hAP ac2 which was used only as Access Point to extend the ISP router’s wireless coverage.
I’d like to know if I can create a second network which routes all traffic of connected clients to my house (not only my house’s LAN addresses).
So, I tried my best:
The final result I wanna achieve is to have some devices (not all of them) both wireless and wired with all traffic going through the VPN tunnel to my first house (light blue arrow), where I have some IP-related services and also local servers.
Other devices (like smartphones, smart tv, etc…) don’t have to be routed on the VPN to save troughput.
I don’t need only the local subnet of “Home 1” to be router but all the traffic coming from that VLAN clients.
Other info: the “Home 1” vm is running a Wireguard instance linked to my mobile devices also. I assign 1 static IP per device, like I did for the Mikrotik hAP ac2 in “Home 2”, so I’d like the Mikrotik to NAT “VLAN 2” connections and route them (with Wireguard VPN) to “Home 1 LAN”.
Actually I have a Wireguard peer handshaking from Mikrotik hAP ac2 to my house, but I don’t know how to route those devices over it.
Its getting a bit clearer but when you try and talk traffic and config at the same time it gets jumbled.
Does the ISP ROUTER/MODEM provide a public IP address or a fixed private LAN IP?
Does your home WAN provide you with a public IP address of a fixed private LANIP.