I have configuration for 2 WAN connections configured for load balance and fail over. There is no firewall filter rules on purpose.|
I have DMZ from my internet providers to the mikrotik.
I want to add wireguard configuration and i want to be able to access my lan network ( 192.168.100.0/24).
Code: Select all
# apr/05/2023 14:53:07 by RouterOS 7.8
# software id = MSE5-ZZKY
#
# model = C53UiG+5HPaxD2HPaxD
# serial number = HE708M3K3P1
/interface bridge
add name=lan
/interface ethernet
set [ find default-name=ether1 ] comment="A1" name=WAN1 \
poe-out=off
set [ find default-name=ether2 ] comment="EASYTV" name=WAN2
set [ find default-name=ether3 ] comment=stefan
set [ find default-name=ether4 ] comment="3rd floor"
set [ find default-name=ether5 ] comment=stefan
/interface wifiwave2
set [ find default-name=wifi1 ] configuration.mode=ap .ssid=Mikrotik5 \
disabled=no
set [ find default-name=wifi2 ] configuration.mode=ap .ssid=Mikrotik \
disabled=no
/interface wireguard
add listen-port=53231 mtu=1420 name=wireguard1
/interface list
add name=WAN
add name=LAN
/ip pool
add name=dhcp ranges=192.168.100.101-192.168.100.250
/ip dhcp-server
add address-pool=dhcp interface=lan lease-time=1d name=dhcp1
/routing table
add fib name=to_WAN1
add fib name=to_WAN2
/interface bridge port
add bridge=lan interface=ether3
add bridge=lan interface=ether4
add bridge=lan interface=ether5
add bridge=lan interface=wifi1
add bridge=lan interface=wifi2
/interface list member
add interface=WAN1 list=WAN
add interface=WAN2 list=WAN
add interface=lan list=LAN
/interface wireguard peers
add allowed-address=192.168.99.2/32 interface=wireguard1 public-key=\
"H4APrAYA7deOVfm2fETQybTL0aOEY23eo9s3kHSBCiE="
/ip address
add address=192.168.1.20/24 interface=WAN1 network=192.168.1.0
add address=192.168.100.1/24 interface=lan network=192.168.100.0
add address=192.168.101.20/24 interface=WAN2 network=192.168.101.0
add address=192.168.99.1 interface=wireguard1 network=192.168.99.0
/ip dhcp-server network
add address=192.168.100.0/24 dns-server=1.1.1.1,8.8.8.8 gateway=192.168.100.1 \
netmask=24
/ip dns
set servers=1.1.1.1,8.8.8.8
/ip firewall mangle
add action=accept chain=prerouting dst-address-list=192.168.1.0/24 \
in-interface=lan
add action=accept chain=prerouting dst-address-list=192.168.101.0/24 \
in-interface=lan
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=WAN1 new-connection-mark=WAN1_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
in-interface=WAN2 new-connection-mark=WAN2_conn passthrough=yes
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=lan new-connection-mark=WAN1_conn \
passthrough=yes per-connection-classifier=both-addresses:2/0
add action=mark-connection chain=prerouting connection-mark=no-mark \
dst-address-type=!local in-interface=lan new-connection-mark=WAN2_conn \
passthrough=yes per-connection-classifier=both-addresses:2/1
add action=mark-routing chain=prerouting connection-mark=WAN1_conn \
in-interface=lan new-routing-mark=to_WAN1 passthrough=yes
add action=mark-routing chain=prerouting connection-mark=WAN2_conn \
in-interface=lan new-routing-mark=to_WAN2 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN1_conn \
new-routing-mark=to_WAN1 passthrough=yes
add action=mark-routing chain=output connection-mark=WAN2_conn \
new-routing-mark=to_WAN2 passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat out-interface=WAN1
add action=masquerade chain=srcnat out-interface=WAN2
/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.1.1 pref-src="" routing-table=to_WAN1 scope=30 \
suppress-hw-offload=no target-scope=10
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
192.168.101.1 pref-src="" routing-table=to_WAN2 scope=30 \
suppress-hw-offload=no target-scope=10
/system clock
set time-zone-name=Europe/Sofia
/system routerboard settings
set auto-upgrade=yes
https://imgur.com/Mi66ZWs
Currently I cannot establish wireguard connection, but I could earlier today, BUT without access to my home network, only ping to router. I was going back and forth with the configuration for long time and at the moment I can't even establish connection with the wireguard interface.
Please help I am desperate.