Community discussions

MikroTik App
 
User avatar
mozerd
Forum Veteran
Forum Veteran
Topic Author
Posts: 920
Joined: Thu Oct 05, 2017 3:39 pm
Location: Canada
Contact:

Road Warrior Config by the Network Berg

Tue May 24, 2022 9:52 pm

Outstanding WireGuard Video by the one and only Network Berg
Using RoS 7.2.3
https://m.youtube.com/watch?v=CH10spRyG ... e=youtu.be
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1537
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Road Warrior Config by the Network Berg

Tue May 24, 2022 10:55 pm

Hmm...

Steve Trujillo:
- "Can you show us the firewall setup for WireGuard? Would it be in the Input chain or the forward? Filter list or nat list?"

The Network Berg:
- Hi Steve, my firewall has no filter rules. The default rules on ROS should also still allow the traffic I think. But you want to make sure that "INPUT" on the Filter List allows the listening port on your firewall since a session is being established to the router's IP. So a rule might look something like: /ip/firewall/filter/add chain=input protocol=tcp/udp dst-port=13231 in-interface="WAN PORT" (Could change interface to destination as well)"

Alexander Chobot:
- "what you mean? you just make "ip firewall filter add chain=input action=accept protocol=udp dst-port=XXXXX place-before=0 in-interface-list=WAN" like rule where XXXXX is wireguard interface port."
 
holvoetn
Forum Guru
Forum Guru
Posts: 6318
Joined: Tue Apr 13, 2021 2:14 am
Location: Belgium

Re: Road Warrior Config by the Network Berg

Tue May 24, 2022 11:09 pm

I hate YT videos...

Protocol= tcp/udp.

Was that really mentioned ?
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1537
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Road Warrior Config by the Network Berg

Tue May 24, 2022 11:15 pm

In the comments. Curious why he called it a Road Warrior Config. It looks like a regular wg tunnel to me...
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21351
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Road Warrior Config by the Network Berg

Wed May 25, 2022 12:45 am

I watched it live stream this morning, its short on detail and content and it was more of an exposure to road warrior setup vice an indepth discussion.
Much better is this article.... - viewtopic.php?p=906311
 
TheNetworkBerg
just joined
Posts: 15
Joined: Mon Sep 30, 2019 9:50 am

Re: Road Warrior Config by the Network Berg

Thu May 26, 2022 7:48 am

In the comments. Curious why he called it a Road Warrior Config. It looks like a regular wg tunnel to me...
"Road Warrior" by definition means someone who might be travelling a lot, this type of wireguard setup allows for a "Road Warrior" to establish a wireguard tunnel to the wireguard server regardless of internet connection or origin. The server is not aware of what connection IPs the client is using since those IPs may be dynamic and it may be changing constantly or be behind a NATTED connection. The biggest point of this setup is just to have matching keys so that the client can establish the tunnel whenever needed to either route all internet traffic through to the WG server or very specific routing, which will require some further tweaking. This provides encryption for your traffic for secure browsing. There are more things that you can do with Wireguard which is why I have 2 other videos besides the "Road Warrior" setup. The links to the whitepaper for Wireguard as the top pinned comment also explains a lot more how Wireguard works if you want to get more in-depth into it.

Who is online

Users browsing this forum: Bing [Bot], erlinden, mkx, Vicus and 28 guests