ALGO VPN X EC2 X DD-WRT Wireguard

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
GP-RJ
DD-WRT Novice


Joined: 29 Jul 2020
Posts: 4

PostPosted: Fri Jul 31, 2020 12:39    Post subject: ALGO VPN X EC2 X DD-WRT Wireguard Reply with quote
Hi there.
This is my first post and first of all TKS A LOT for all the information hanging around.

I dont have much (or any) knowledge about networking but after a week of research i finally build an AWS EC2 instance using ALGO VPN.

From the beginning i was kind of worried but worked like a magic and know i have an AWS instance running as a VPN server and Algo already generated the clients files configuration for me.

Thats the problem.

On my macbook i am using wireguard and it was easy. Just config import.

Same for IOS. Just a qrcode scanning.


BUT, when i try to create a tunnel in the router, i go to the tunnels sections, select WIREGUARD, but the LOCAL PUBLIC KEY is already filled by default. Theres no way to cut it and paste my own code (wich ALGO generate for me)

I assume that the iNTERFACE PRIVATE in the client config file is the LOCAL PUBLIC key in the router.

Am i right? I am attaching the config file view and my router view.

Tks again folks
Sponsor
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14244
Location: Texas, USA

PostPosted: Fri Jul 31, 2020 13:21    Post subject: Reply with quote
Which router, what build number....
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12915
Location: Netherlands

PostPosted: Fri Jul 31, 2020 15:16    Post subject: Reply with quote
We can help you better if you read and follow the forum guide lines:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

(which will tell you to always state router model and build number and not to use the router database)

You are using an old build that is for sure newer builds can alter keys and much more.

See my signature at the bottom for necessary documentation about wireguard

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Fri Jul 31, 2020 15:22    Post subject: Reply with quote
The Local Public Key is created automatically from the Local Private Key.
_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
GP-RJ
DD-WRT Novice


Joined: 29 Jul 2020
Posts: 4

PostPosted: Fri Jul 31, 2020 16:41    Post subject: Reply with quote
egc wrote:
We can help you better if you read and follow the forum guide lines:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

(which will tell you to always state router model and build number and not to use the router database)

You are using an old build that is for sure newer builds can alter keys and much more.

See my signature at the bottom for necessary documentation about wireguard


Hi all. Tks for the input.

My router is an asus rt 3200 and yes i was using an old firmware.

I updated it and know its running Firmware: DD-WRT v3.0-r43904 std (07/23/20)

After the update i received a handshake. But no data in as the attached. transfer: 0 B received, 6.21 KiB sent

I read and download the guide from your signature. About the changeset 43029 ..do i need it since my version is 43904?

If the answer is yes, i dont a have a clue how to do it. I see green and red lines. I suppose that the green lines should replace the red ones... do i have to copy/paste and run at the command shell? Should i edit mannualy?

Sorry for my naivety.

Again. Tks and keep on rockin in a free world.
GP-RJ
DD-WRT Novice


Joined: 29 Jul 2020
Posts: 4

PostPosted: Fri Jul 31, 2020 16:46    Post subject: Reply with quote
Just to make it clear. I have the same VPN server working perfectly on my Macbook and Iphone using wireguard app.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12915
Location: Netherlands

PostPosted: Fri Jul 31, 2020 17:00    Post subject: Reply with quote
Sure but if you do not follow the instructions it will not work

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324624

At least your Allowed IP's are wrong, I cannot check other settings as you blurred it (understandably)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
GP-RJ
DD-WRT Novice


Joined: 29 Jul 2020
Posts: 4

PostPosted: Fri Jul 31, 2020 21:54    Post subject: Reply with quote
egc wrote:
Sure but if you do not follow the instructions it will not work

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324624

At least your Allowed IP's are wrong, I cannot check other settings as you blurred it (understandably)


Hi Guys
Tks again

I made a new configuration using another client config and its working now. I made sure to double check blank spaces and its working.

The only issue is that my down and up rates are very low. I was searching and found that its MTU related. I will make some tests and post it here!

I have 250 down and my top speed now using wireguard is 20mbs.

Well, i found this
https://github.com/trailofbits/algo/issues/216
https://www.zeitgeist.se/2013/11/26/mtu-woes-in-ipsec-tunnels-how-to-fix/
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12915
Location: Netherlands

PostPosted: Sat Aug 01, 2020 6:35    Post subject: Reply with quote
See page 17 of the ddwrt wireguard server setup guide

MTU size problems (Connection, but no traffic, hang, slow loading, or no streaming media)
MTU problems often manifest themselves as connections which hang during periods of active usage, or does
not load the whole page when browsing. Or you can connect but not see or use streaming media (like an IP
Camera) or your connection is unexpected slow.
The MTU (Maximum Transmission Units) is the maximum datagram size in bytes that can be sent
unfragmented over a particular network path. Wireguard requires that packets be sent unfragmented.
MTU size is set in the GUI and is standard 1460 for IPv4 and 1420 for IPv6. But sometimes this is too high
especially if you are using connection via LTE.
You can try lowering the MTU with trial and error i.e. start at 1024 (for IPv6 the minimum MTU is 1280) and
work your way up or use the approach describe at: https://www.sonassi.com/help/troubleshooting/setting-correct-mtu-for-openvpn
Make sure to reboot the router after changing!

Checking the right MTU size:
https://hamy.io/post/0003/optimizing-openvpn-throughput/

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum