I am attempting to troubleshoot a couple issues I am seeing in using Zerotier with rOS v7.17 where only some connections are passing as expected.
A little background on my network configuration. I utilize multiple Zerotier networks for different purposes including remotely accessing my home network. One of these is provisioned through Zerotier’s online service while I run a self hosted network controller for the remainder. The specific network I am seeing this problem with is a standalone network for the purpose of interconnecting deployable assets no matter their geographical or physical network location. This network ID is provisioned through my self hosted network controller and has multiple peers including the network controller server on my home network. There is no configured routing or forwarding for access to my home network.
I provisioned a recently purchased hAP ax2 for use on this Zerotier network last weekend. During the setup I ended up upgrading to rOS v7.17.1. The router is now currently at v7.17.2 with no improvement. The router is correctly provisioned in the network controller and is reachable via the Zerotier network from the network controller machine and other peer devices. This includes icmp ping test, ssh, and access to the web GUI. However, I am unable to reach any devices via the Zerotier network from the LAN side of the hAP ax2. But, from the LAN I am able to reach the web GUI using the Zerotier assigned address.
As I am working on this at home, the hAP ax2 is physically connected to my home network, and from a device on the LAN side of the router I found I am able to connect through to home network devices.
In the hAP ax2 configuration, the Zerotier interface is configured as LAN in the Interfaces>Interface List table, identical to the bridge interface. In the firewall settings I have added two filter rules to accept traffic from the Zerotier interface for both the input and forward chains and moved them toward the top of the list. Under IP>Routes the list correctly shows the expected routes for the bridge interface, the WiFi client interface, the Zerotier interface, and the default gateway route.
On a computer connected to the LAN side of the hAP ax2, the IP and route as assigned by DHCP is correctly shown as only the router’s LAN subnet and default gateway of the router.
If needed, I can provide more specific configuration info. Given that routing works as expected with the exception of Zerotier I am led to believe it may be firewall related but don’t see what would be needed. Appreciate any advice in troubleshooting further.
