Community discussions

MikroTik App
 
mawebi
just joined
Topic Author
Posts: 2
Joined: Wed Oct 28, 2020 11:50 pm

MT Router as Wireguard Client & Benchmarks

Thu Oct 29, 2020 12:02 am

Hi,

today I tried to use the MT router as wireguard client (peer) and worked really easy. I had problems with MTU (I guess), but with the mangle entry (see #fix MTU) it worked like a charm:
# add interface
/interface wireguard
add listen-port=5555 mtu=1420 name=wireguard1 private-key=\
    "<private key MT peer>"
 
# add peer
/interface wireguard peers
add allowed-address=0.0.0.0/0,::/0 endpoint=<ip of wireguard server>:5555 interface=\
    wireguard1 public-key="<pub key wireguard server>"
 
# add ip to interface
/ip address
add address=10.200.200.2/24 interface=wireguard1 network=10.200.200.0
 
# nat
/ip firewall nat
add action=masquerade chain=srcnat out-interface=wireguard1
 
# fix MTU
/ip firewall mangle
add action=change-mss chain=forward new-mss=clamp-to-pmtu out-interface=wireguard1 protocol=tcp tcp-flags=syn
Afterwards I changed the default route to the IP 10.200.200.1 (wireguard server) and added a static router to reach the server itself without the tunnel (see viewtopic.php?t=73775). Now the whole traffic is tunneled.

For the benchmark, I used my internet connection (100mbit), with the following results:
* RB951G-2HnD - max. 65mbit/s at 99% CPU
* hEX (RB750Gr3) - max. 95mbit/s at 50-60% CPU
 
cascom
just joined
Posts: 7
Joined: Wed Oct 24, 2018 5:22 am
Location: Texas
Contact:

Re: MT Router as Wireguard Client & Benchmarks

Thu Nov 19, 2020 4:20 pm

I have a Wireguard subsciption vis OVPN.net and trying to use their config file to enter my info into my SXT LTE6 running 7.1
I'm using Winbox, have not mastered CLI yet.
I can see wireguard in my interfaces list.
Do I now need to add it to the interface list?
Sorry, I'm real new.

Who is online

Users browsing this forum: bastys, mducharme, nescafe2002, xvo and 11 guests