Community discussions

MikroTik App
 
zhouck
just joined
Topic Author
Posts: 12
Joined: Wed Sep 06, 2023 2:45 pm

Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 12:39 pm

1. Mikrotik hap AC^2
2. Wireguard installed, Mikrotik has wg IP 174.16.0.1
3. IP address pool 174.16.0.0/24
4. Peers could comunicate with each other but when I try to open Winbox (174.16.0.1) got connection refused
 
erlinden
Forum Guru
Forum Guru
Posts: 2658
Joined: Wed Jun 12, 2013 1:59 pm
Location: Netherlands

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 1:05 pm

Sounds like your firewall is blocking this traffic (which it should). Have you added the Wireguard interface to the LAN Interface List? Assuming you are using this Interface List in the firewall?

Otherwise, please share your config:
/export file=anynameyoulike
Remove serial and any other private information.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1611
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 1:31 pm

@zhouck, I'm just guessing here, but make sure you've added the Wireguard network interface to: Interfaces > Interface List > LAN
 
zhouck
just joined
Topic Author
Posts: 12
Joined: Wed Sep 06, 2023 2:45 pm

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 2:11 pm

Yeah, adding to interface list LAN fix the issue. Am I introducing any security issue with such solution? Why Wireguard not added to LAN by default?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22004
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 2:19 pm

Your config is wrong, a reasonable request to post it has been ignored.
 
erlinden
Forum Guru
Forum Guru
Posts: 2658
Joined: Wed Jun 12, 2013 1:59 pm
Location: Netherlands

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 2:35 pm

Am I introducing any security issue with such solution?
That depends. Do you want all Wireguard peers to be able to connect to your router?
Why Wireguard not added to LAN by default?
Well...because that would be a very stupid default.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22004
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Access to Mikrotik from wireguard peer

Mon Jun 17, 2024 2:46 pm

Concur, there are many instances where wireguard is to a third party server and in that case it makes more sense for WG to part of the WAN interface list, and thus the default masquerade rule covers local subnet to wireguard traffic.

Who is online

Users browsing this forum: No registered users and 24 guests