Posted: Fri Oct 15, 2021 16:35 Post subject: Wireguard behind gateway not accessible
I have wireguard running on a DD-WRT router (WNDR4300 build r47495 9-28-21) that sits behind my gateway router DD-WRT v3.0-r39960M kongac (06/08/19). I am able to connect my Android mobile to wireguard from the LAN but not the WAN. I can't figure out why.
From the WAN, I can see the initial packets arrive at the wireguard router but nothing gets sent back.
Joined: 18 Mar 2014 Posts: 12889 Location: Netherlands
Posted: Fri Oct 15, 2021 19:34 Post subject:
On the Gateway router (which is running and old and obsolete build with security issues) I see DNAT rule for port 51820 to 10.47.67.10 which I presume is the WAN IP address of your WG router.
I do not see a FORWARD rule but I suppose it is there and the port forwarding on the Gateway router is working.
On the WG router I see a strange DNAT rule about port 58120 are you also port forwarding on that router?
It looks like you are defining an endpoint on the server side (to the server itself) that is not in the manual, so delete the endpoint and also delete keep alive.
The server is only listening
Under allowed IP's only the WG IP address of the client will do so probably 10.4.0.5/32
(This because clients usually NAT over the WG interface)
If the Port Forward on the Gateway works, then just following the WG server setup guide should do the trick
I spent the last few days upgrading the gateway router to r47495 (9-28-21) and ensuring all works. With that behind me, I returned to the problem described above.
I removed the firewall settings on the wireguard router that were not needed but added confusion. I set wireguard keep alive to 0.
I removed my manual port forwards from the gateway router and replaced them with a GUI port forward for udf wan-ip:51820 -> 10.47.67.10:51820 (wireguard router).
Behaviour is the same. I can connect to wg from the LAN but not from the internet. Packets are being seen on the router coming in but no packets are replying.
This is very strange. Since I upgraded the gateway, it now has wg capabilities. I configured the gateway wg and it works perfectly. I think I'll stop trying to debug the wg forward issue.
Thanks for the help and the advice to U/G the gateway.
Joined: 31 Jul 2021 Posts: 2146 Location: All over YOUR webs
Posted: Mon Nov 08, 2021 14:35 Post subject:
I would give the latest build a try DD-WRT v3.0-r47618 std (11/05/21)
Quite a few wireguard patches went in courtesy of egc
If that will help or if the remaining issues are configuration side I dont know, I will consider myself a wireguard setup/operation ignorant as I haven't yet tried it.