Community discussions

MikroTik App
 
mculjak
just joined
Topic Author
Posts: 2
Joined: Tue Jul 18, 2023 3:14 pm

LAN connection through WIREGUARD

Wed Nov 22, 2023 5:56 pm

We are using MikroTik LtAP LTE6 kit in our network as LTE AP where several devices are connected via Wifi to Internet and cloud services. Also we are using wireguard VPN to connect to the system remotely and we can connect to MikroTik user interface via VPN but other devices which are connected to MikroTIK LAN port are not reachable via wireguard (VPN) - only if we are connected to MikroTik WiFi od via LAN cable. Is there some option to bridge wireguard interface and LAN interface or something like that?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19395
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: LAN connection through WIREGUARD

Wed Nov 22, 2023 7:52 pm

Depends on the firewall rules........
How did you ensure the wireguard could reach the device and config it???
 
mculjak
just joined
Topic Author
Posts: 2
Joined: Tue Jul 18, 2023 3:14 pm

Re: LAN connection through WIREGUARD

Thu Nov 23, 2023 5:01 pm

I upload my configuration in file.
I can access the mikrotik configuration and ping the mikrotik via wireguard from my phone and laptop, but I cannot access or ping other devices via wireguard that are connected by an ethernet cable (LAN) on the same switch as MIKROTIK and have IP addresses 192.168.88.xx.
You do not have the required permissions to view the files attached to this post.
 
templlama
just joined
Posts: 12
Joined: Thu Nov 23, 2023 1:46 pm

Re: LAN connection through WIREGUARD

Thu Nov 23, 2023 9:13 pm

(1) Not sure why you have a pool called VPN ranges?? Wireguard only gets an address in the MT installation, nothing else, there is no DHCP etc...

OKAY, please look at this and you TELL ME what is wrong....... You will want to kick yourself!! ;-)

/ip address
add address=192.168.88.1/24 comment=defconf interface=bridge network=\
192.168.88.0
add address=192.168.88.1 interface=wireguard1 network=192.168.88.0


YOU NEED to decide what is easier to change.
LAN to 192.168.89.0 ( my recommendation)
OR
Wireguard to 192.168.9.0

(2) The router is the wireguard server and thus do not need second masquerade rule.

(3) IP routes have to be fixed there is no need for you to add a wireguard IP route.
The router automatically creates one for local interfaces
( are there remote subnets requiring access or local users need to reach..........dont think so! )

Who is online

Users browsing this forum: No registered users and 4 guests