Community discussions

MikroTik App
 
emarj
just joined
Topic Author
Posts: 4
Joined: Thu Aug 29, 2024 10:20 am

Understanding Back to Home VPN (Wireguard) mysterious peer

Sat Nov 23, 2024 7:54 pm

Mikrotik BTH generates Wireguard configuration files with an additional peer at the bottom with AllowedIPs set to 0.0.0.0/32 and a very odd PublicKey as follows. Could someone explain what purpose does this peer entry serve?
[Interface]
...

[Peer]
...

[Peer]
PublicKey = //////////////////////////////////////////8=
AllowedIPs = 0.0.0.0/32
Endpoint = dsdsd.sn.mynetname.net:12345
PersistentKeepalive = 15
Last edited by emarj on Mon Nov 25, 2024 11:23 am, edited 1 time in total.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22084
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Understanding Back to Home VPN (Wireguard) odd peer

Sat Nov 23, 2024 8:31 pm

From my understanding, one uses your smartphone to create an initial tunnel while behind the router.
Then one can use the smartphone BTH app ( under MANAGED SHARES) to generate qr codes or config files for other smart phones/laptops etc...... (laptops use the wireguard app itself).

THe router is capable of generating one QR code/config file for a remote user and maybe that is what you are asking about??
 
emarj
just joined
Topic Author
Posts: 4
Joined: Thu Aug 29, 2024 10:20 am

Re: Understanding Back to Home VPN (Wireguard) odd peer

Mon Nov 25, 2024 11:23 am

Hi @anav, thanks for the reply.

The functioning of BTH it is pretty clear to me, my question is about this "mysterious" peer with PublicKey //////////////////////////////////////////8= that is being added.

If I remove this from the config everything works regardless. I don't understand the need of a second peer... Also I don't understand 0.0.0.0/32 to be honest. Has this something to do with the Mikrotik Relay functionality in case the WAN IP is not public?
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26922
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: Understanding Back to Home VPN (Wireguard) mysterious peer

Mon Nov 25, 2024 11:31 am

If you have direct access to your router (it has public IP) then one connection is enough, but if your device is behind NAT or has non public IP, the connection will go over our MikroTIk Relay service, this is what the other config is for.
 
emarj
just joined
Topic Author
Posts: 4
Joined: Thu Aug 29, 2024 10:20 am

Re: Understanding Back to Home VPN (Wireguard) mysterious peer

Mon Nov 25, 2024 12:25 pm

If you have direct access to your router (it has public IP) then one connection is enough, but if your device is behind NAT or has non public IP, the connection will go over our MikroTIk Relay service, this is what the other config is for.
Thanks for the reply. I suspected that, thanks a lot for clarifying. :)
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22084
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Understanding Back to Home VPN (Wireguard) mysterious peer

Mon Nov 25, 2024 7:11 pm

Thank you emarj, I misunderstood your question and gave you a duff answer, now I understand that additional BTH config, and will be able to assist others more accurately down the line.
Thanks to @Normis, for clearing that up................... Suggest you add it to the MT document section on BTH so its clear to all readers as well.

Who is online

Users browsing this forum: No registered users and 69 guests