I have a main site with activated back to home function via wireguard. Works perfect with my mobile device.
I have also a second “remote” site where I want to put a mikrotik router. I would like to connect from the remote site via wireguard to the main site to access resources on the main site.
Would it be enough to add a new user to the back to home setup, and set up a wireguard device on the remote site with connection data of the addes BTH user? Will this work or is there more configuration needed for a permanent connection?
Second question. If it works, I can access devices on the main site from the remote site. But will it be also possible to connect devices on the remote site from the main site with this BTH connection? I have different IP networks on the two sites.
A new user can be assigned and its configuration can be added to a new remote Mikrotik. As far as I'm aware, the configuration has to be added manually to the new remote device.
The BTH is explicitly for connecting a remote device (as in a single one) to your main network. This means that with an appropriate srcnat rule, the devices behind the new remore router will be able to access the main network, but they will all show up with a single ip (the one assigned to the new BTH user.)
I’ve installed the Mikrotik Router (hap ac) on the remote site. I was able to establish a Wirequard Connection to the main site and I can reach all devices from the remote site on the main site.
From the main site, I can ping and connect the remote router via the wireguard tunnel perfectly. But I can’t reach devices behind the remote router.
I tried this on the remote site:
I’ve added nat masquerading for incoming traffic from the wireguard tunnel to the local network on the remote site (192.168.178.0/24).
On the main site I’ve added a static route for the remote subnet via the bth-vpn interface: