Community discussions

MikroTik App
 
cdesz
just joined
Topic Author
Posts: 11
Joined: Thu Nov 01, 2012 4:10 pm

Is there a way to set local ip-address of wireguard tunnel?

Tue Jun 11, 2024 8:00 pm

I have two providers and bgp network
ISP1: 1.1.1.1/30
ISP2: 2.2.2.1/30
my net: 3.3.3.1/24
I want customers to connect to wireguard on 3.3.3.1, but my router sends wg-traffic from addresses 1.1.1.1 or 2.2.2.2 depending on which route selected.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21918
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Is there a way to set local ip-address of wireguard tunnel?

Tue Jun 11, 2024 11:54 pm

The ISP route is ONLY used for the initial handshake. After that traffic is sent through the tunnel which is dependent upon the wireguard address structure additional routes if necessary and applicable firewall rules. So access to your LAN from external wireguard users or another wireguard routers subnet is perfectly feasible as well as local LAN traffic heading out the tunnel to another remote LAN etc................
 
cdesz
just joined
Topic Author
Posts: 11
Joined: Thu Nov 01, 2012 4:10 pm

Re: Is there a way to set local ip-address of wireguard tunnel?

Thu Jun 13, 2024 12:03 pm

But it does not work that way
If on customer device endpoint configured is 3.3.3.1 then I see packet received from cust_ip to 3.3.3.1 but reply send to cust_ip from 1.1.1.1 and it seem ignored by customer device.
Is setting pref-src in routes fetched by bgp only solution?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21918
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Is there a way to set local ip-address of wireguard tunnel?

Thu Jun 13, 2024 11:08 pm

You are spouting gibberish. If you want to have a serious discussion
a. provide a diagram
b. explain the wans at both ends ( static, dynamic, public or private)
c. provide configs of MT devices and remote wireguard device setttings
(minus serial number, any public wanip information, keys etc.)
 
User avatar
jvanhambelgium
Forum Guru
Forum Guru
Posts: 1114
Joined: Thu Jul 14, 2016 9:29 pm
Location: Belgium

Re: Is there a way to set local ip-address of wireguard tunnel?

Fri Jun 14, 2024 12:00 am

what is "a bgp network" ?
Is 3.3.3.x/24 a pieces of your (public) PI-space ?
Is this "Internet" connected ?

Or is that 3.3.3.x prefix coming in via either ISP1 or ISP2

Who is online

Users browsing this forum: No registered users and 22 guests