Community discussions

MikroTik App

Search found 9 matches

by mszulc
Sun Jan 23, 2022 10:33 pm
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

Re: NAT wireguard-originated traffic

So I'm answering to myself ;-)

Works because it is already being tracked. If I flush all connections it stops working

So:
1. Wireguard needs SRCNAT and is not doing NAT internally
2. I need to double-check before posting
by mszulc
Sun Jan 23, 2022 10:28 pm
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

Re: NAT wireguard-originated traffic

That is good explanation - but next question arrives:
why it works even with all NAT rules disabled? It looks like wireguard is doing NAT internally.
by mszulc
Sun Jan 23, 2022 10:15 pm
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

Re: NAT wireguard-originated traffic

btw: it works and is not using masq/snat rules. I can disable them. It is strange, I don't understand what is changing source address.
Does wireguard have it's own MASQ?
by mszulc
Sun Jan 23, 2022 10:09 pm
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

Re: NAT wireguard-originated traffic

No they don't. This is the first rule.

BUT - the problem is fixed now. All I did is to restart the router. So - definitelly - there is some kind of problems in 7.1.1
by mszulc
Sun Jan 23, 2022 8:25 pm
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

Re: NAT wireguard-originated traffic

anav, thanks for reply but I don't really understand Your post nor mentioned article. The situation here is simple: - R1 is a "client". R2 is "gateway". - R1 and R2 does have own internet connection, but part of R1-originated internet traffic has to go via R2, not by local link o...
by mszulc
Sun Jan 23, 2022 10:02 am
Forum: General
Topic: NAT wireguard-originated traffic
Replies: 10
Views: 7354

NAT wireguard-originated traffic

Hi I've set up two routers R1 and R2 (ROS 7.1.1) and connected them with wireguard. Tunnel works fine, I can ping both endpoints. I'm trying to use it as a kind of VPN, forwarding part of the traffic from R1 via R2 to the internet. So - I've set up routes, firewall rules. Firewall counters on R2 sho...
by mszulc
Mon Sep 18, 2017 1:29 am
Forum: General
Topic: DSCP for DHCP (Orange FTTH problem) - once again
Replies: 0
Views: 1246

DSCP for DHCP (Orange FTTH problem) - once again

I know it has been brought up many times with no reply from Mikrotik team. I know that it is not standard, according to TCP/IP specs, but I need to have an option for DSCP to be set to 6 for MT DHCP requests. If You are using Orange FTTH (in Poland at least) it is possible to use Mikrotik device con...
by mszulc
Fri Mar 25, 2016 8:31 pm
Forum: Announcements
Topic: v6.35rc [release candidate] is released, new wireless package!
Replies: 536
Views: 188749

Re: v6.35rc [release candidate] is released, new wireless package!

I had the same 'non working' wifi problem as described by others with rep package. End user device works good for some time and suddenly looses connectivity while showing wifi as connected. Simple disconnect/connect solves the problem for some time (5-10 minutes). If left with no intervention for so...
by mszulc
Mon Jun 23, 2014 2:36 pm
Forum: Wireless Networking
Topic: CAPSman and DTLS teardown
Replies: 3
Views: 4680

CAPSman and DTLS teardown

HI All, I've just started a test setup for CAPS manager. Network consists of: - one RB2011UAS-2HnD (will act as Caps manager) - one RB333 (will act as Caps client) both of them running 6.15 with wireless-fp enabled. They are connected via ethernet link, same subnet with no filtering. I've tried to s...