Hi All,
I am brand new to Mikrotik, stepping up from OpenWRT. My new router works well out of the box and I want to add a commercial Wireguard VPN that I use to force all outgoing traffic over. So Mikrotik will act as the VPN client. I am running RouterOS v 7.20.1.
I carefully followed a YouTube tutorial online by someone who really knew what they were doing (The Network Berg). I added the public/private wireguard keys, set up a Peer, and the DNS. When I got to the Routing Table, there was something different that I could not do as the tutorial had.
The IP address of my ISP's modem/router is 192.168.1.254 and serves are the gateway for all Mikrotik traffic (destination address 0.0.0.0/0) headed for the internet. In the tutorial, they simply deleted that route (0.0.0.0 to 192.168.1.254) so they could assign (0.0.0.0/0) to wireguard. However, in my case, when I try and remove the connection between 0.0.0.0/0 to 192.168.1.254, it tells me that it "cannot remove dynamic route created by a different owner 0.0.0.0/0->192.168.1.254". Additionally, for this route, I cannot make any changes at all including changing the distance, disabling it, etc. So now I have 0.0.0.0/0 as the destination address for 2 separate records, which doesn't look right to me.
None of my traffic is going through the wireguard VPN. In the Peer record, Tx packet and Rx packet both read 0. I've tried poking around a bunch, and I don't know what to do. There are some posts similar to mine, either the problems are a bit different or the answers are way over my head. I'm hoping that there's a relatively simple solution that someone can see.
The wireguard endpoint is 206.217.206.16 and the wireguard IP address is 10.70.155.225. I can see that my wireguard is a static connection.
Here is the routing table as it's set up:
[admin@MikroTik] /interface/list> /routing/route print
Flags: A - ACTIVE; c - CONNECT, s - STATIC, d - DHCP; + - ECMP
Columns: DST-ADDRESS, GATEWAY, AFI, ROUTING-TABLE, DISTANCE, SCOPE, TARGET-SCOPE, IMMEDIATE-GW
DST-ADDRESS GATEWAY AFI ROUTING-TABLE DISTANCE SCOPE TARGET-SCOPE IMMEDIATE-GW
As+ 0.0.0.0/0 wireguard ip main 1 30 10 wireguard
Ad+ 0.0.0.0/0 192.168.1.254 ip main 1 30 10 192.168.1.254%ether1
Ac 10.70.155.225/32 wireguard ip main 0 10 5 wireguard
Ac 192.168.1.0/24 ether1 ip main 0 10 5 ether1
Ac 192.168.88.0/24 bridge ip main 0 10 5 bridge
As 206.217.206.16/32 192.168.1.254 ip main 1 30 10 192.168.1.254%ether1
Ac ::1/128 lo ipv6 main 0 10 5 lo
Ac fe80::/64 bridge ipv6 main 0 10 5 bridge
Ac fe80::/64 wireguard ipv6 main 0 10 5 us-dal-wg-507
Ac fe80::/64 ether1 ipv6 main 0 10 5 ether1
A lo link main 0
A ether1 link main 0
A ether4 link main 0
A bridge link main 0
A wireguard link main 0
