I have the following setup:
Site A
* Mikrotik-Router as ISP Router and wireguard server
* ... has LAN: 192.168.200.0/24 with IP 192.168.200.1
* ... uses Wireguard-VPN: 192.168.201.0/24 with IP 192.168.201.1
* ... has static route to Site B LAN 192.168.0.0/24 via 192.168.201.3
Site B
* Linux machine, running Wiregards as Peer to conenct to Site A (which works)
* ... uses VPN Peer IP: 192.168.201.3
* ... has LAN: 192.168.0.0/24 with IP 192.168.0.133
* Site B runs a AVM FritzBox (which also provides the 192.168.0.0/24 network and is it's default gateway) for internet connectivity and has a static route configured: 192.168.200.0/24 via Gateway 192.168.0.133 (=Linux Machine with Wireguard VPN Peer)
What is working:
* Site B Linux Machine can ping Wireguard VPN 192.168.201.x network without any issue.
* Site B Linux Machine can ping Site A LAN 192.168.200.x network without any issue.
* Any PC on Site A can ping Site B's VPN peer 192.168.201.3
What is not working:
* From Site A I cannot ping on any host any 192.168.0.x IP --> Destination Host Unreachable
* From Site A Mikrotik Router Terminal I cannot ping 192.168.0.133 or any other IP from Site B LAN. --> Host unreachable
When I tcpdump the traffic in the wireguard interface on Site B's Linux Machine, I cannot see any ICMP traffic to/from 192.168.0.x Only 192.168.201.x is visible.
So, from my understanding, there is something wrong with my route on the mikrotik router to 192.168.0.0/24 network. No 192.168.0.0/24 traffic is not routed to SIte B's VPN peer.
Routing table in Site A's mikrotik router looks like this:
Code: Select all
Flags: D - DYNAMIC; I, A - ACTIVE; c, s, v, y - COPY; H - HW-OFFLOADED
Columns: DST-ADDRESS, GATEWAY, DISTANCE
# DST-ADDRESS GATEWAY DISTANCE
[...]
0 As 192.168.0.0/24 192.168.201.3 1
[...]
I would be pleased if anyone can enlighten me ...
br,
Alex