Community discussions

MikroTik App
 
knudch
just joined
Topic Author
Posts: 2
Joined: Sun Aug 13, 2023 12:08 am

Connect to router LAN side web interface from wireguard tunnel

Thu Mar 21, 2024 10:30 pm

Maybe a "stupid" question..

I have hp AX2 router on Public IP (fiber network)
Have a few Wireguard tunnels set up for remote access from clients

Every thing works as expected...
WG clients can connect to LAN clients and vice versa
WG clients can connect to other WG clients
WG clients can ping Router on LAN IP 10.2.1.5 and on WG interface 10.2.3.5 (Clients has address 10.2.3.x)

But WG clients can not connect to Router WEB interface...connection time out
Connection is http://10.2.3.5 or ssh ...
Firewall setup is straight forward for a Home router
What information shall I provide to get a advise ?

Br
Knud
 
holvoetn
Forum Guru
Forum Guru
Posts: 5500
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Connect to router LAN side web interface from wireguard tunnel

Fri Mar 22, 2024 12:51 am

Config perhaps ?
Most likely there is no input accept rule for your wireguard interface.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19409
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Connect to router LAN side web interface from wireguard tunnel

Fri Mar 22, 2024 2:57 am

In general one should set the Router ( assuming server for handshake ) the wireguard interface as part of the LAN interface, that then usuallly, through fw rules, allows RWs to access internet via FW rules and DNS services via input chain rules.
However your request is to config the router, and in that case input chain rule. BUT, do you WANT all RWs to have that access, NO just the admins remote RW accounts.
So interface=wireguard src-address=X or src-address-list=admin etc...
 
knudch
just joined
Topic Author
Posts: 2
Joined: Sun Aug 13, 2023 12:08 am

Re: Connect to router LAN side web interface from wireguard tunnel

Sat Mar 23, 2024 12:45 pm

In general one should set the Router ( assuming server for handshake ) the wireguard interface as part of the LAN interface, that then usuallly, through fw rules, allows RWs to access internet via FW rules and DNS services via input chain rules.
That was what I was looking for...giving the WG clients same access as the LAN clients

Thanks

Who is online

Users browsing this forum: Ahrefs [Bot], Jhosua123 and 36 guests