Hello, I want to create something like “transparent WireGuard VPN”.
I have MikroTik at home connected “indirectly” to fixed public IP address (I mean that the MikroTik has an address like 10.3.x.x/24 from my provider and he forwards all from my public IP 188.x.x.x to this address - this works, I already have some rules that forwards traffic to several home devices that I want to reach at my public address). Let’s call this “home” MT.
Then I have some “mobile” Mikrotik (actually it’s hEX lite - RB750r2). It has 5 ports, port 1 for “internet” by default. I’ve created WireGuard1 link between this “mobile” and “home” MikroTik in a way that when “mobile” MikroTik connects to the internet on port 1 (for testing purposes I use T-Mobile external router, but in a final configuration it can be anything that “provides internet”, like StarLink or any other provider), then the “mobile” MT connects to the public IP addres 188.x.x.x and it goes into the “home” MT. The connection is established and it works. It does not have IP addresses on the Wireguard1 interfaces since I’ve read on this forum that it’s not really necessary. I’d like to keep it that way, if possible.
Then I created two bridges: bridge_2,3 for ports 2 and 3 and bridge_4,5 for ports 4 and 5. The Idea is that bridge_4,5, which has “default” IP address 192.168.88.1/24 and provides DHCP server in that range, would behave like the default bridge created in default configuration on all four ports (2-5). That means anything that connects to theese ports will go to the internet as normal - the internet, that connects to the port 1. This works now.
For the second bridge bridge_2,3 I want anything that connects to the ports 2 and 3 will go to the internet through the WireGuard connection “transparently”. Internal “LAN” network on the “home” MT has IP address 192.168.22.88/24 (88 is the MikroTik itself and works as one of my “default” gateways, primarily for the devices needed to be reachable on the public IP address) and I want that ports 2 and 3 on the “mobile” MikroTik will use this “home” MikroTik as default gateway. Whether the “mobile” MT will have another subnet (like 192.168.104.0/24) on the bridge_2,3 and routing will be possible between “home” MT and “mobile” MT, or clients on bridge_2,3 will also have IP address in range of 192.168.22.xx/24, doesn’t matter (for me). The only thing what is needed is that all devices at home (192.168.22.xx) can communicate with all devices at “mobile” at ports 2,3 (and the “mobile” MT as well) - and of course to the internet through my home provider. Somehow I think that the solution with the extra subnet at bridge_2,3 will be better - I already have this bridge configured in that way and DHCP server (in “mobile” MT) provides addresses in that range to clients connected to ports 2 and 3.
Anyway I don’t have a clue how to configure that
. So I’d like some kind soul to help me, please.
PS: I apologize for my English, it’s not my primary language, still learning.
