ER707-M2 and AX55 Wireguard VPN issue

ER707-M2 and AX55 Wireguard VPN issue

ER707-M2 and AX55 Wireguard VPN issue
ER707-M2 and AX55 Wireguard VPN issue
2024-09-18 09:25:04 - last edited 2024-09-19 06:52:25
Model: ER707-M2   Archer AX55 Pro  
Hardware Version:
Firmware Version:

Hey all,

 

Looked through the forum but didn't find anything close to my case so here I am.

 

Got the following scenario:

ER707-M2
LAN1: 192.168.10.1/24

PC1: 192.168.10.99

WG1: 10.10.10.1

 

 

AX55 PRO

LAN2: 192.168.100.1/24

PC2:192.168.100.96

WG2: 10.10.10.2

 

I have a ER707-M2 in one location and a AX55 PRO in another location. Until now I used OpenVPN to connect to the AX55 for file sharing. Recently I got a ER707-M2 and I'm trying to connect the 2 via Wireguard but got some weird issues. Created the interfaces on both routers, added the peers, but when it comes to checking connection via sites on the tunnel I can't get anything. On the ER707-M2 I've set as the allowed IP addresses 10.10.10.0/24 and the remote subnet with the same public key, on the AX55PRO I've set as the allowed addresses 0.0.0.0/0.

 

Case 1, I'm able to ping LAN2 from the WG1, and I can see on PC2 that the ICMP requests are originating from WG1, but when I try on PC2 to ping WG1, I cannot. In the AX55PRO routing table I can see that a route towards the 10.10.10.0/24 network is made to the WINS interface but I can't add a route manually towards LAN1

 

Case 2, If on the ER707-M2 I'm setting as the allowed IP address 0.0.0.0/24 I'm able to ping anything from LAN1 to LAN2 but I also have all of my traffic directed to LAN2, as in if I check my public IP, is the one at the AX55 side.

 

What I'm trying to achieve is that when I'm trying to access the internet from either LAN, use the public IP from that location, when it comes to accessing content from the remote network, use the WG tunnel.

 

Tried to do the same thing over OpenVPN, couldn't it and I want to go for Wireguard due to the increased bandwidth.

 

Thanks!

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER707-M2 and AX55 Wireguard VPN issue-Solution
2024-09-19 06:19:38 - last edited 2024-09-19 06:52:25

So the documentation for the AX55 is dumb.

 

The tunnel works but I had to enable a specific client on the AX55 to access the VPN -.-"

 

That's why I couldn't establish the connection.

 

All good, for the ones that will come across the same thing, MAKE SURE THAT AFTER YOU SET UP THE TUNNEL YOU ENABLE A DEVICE TO ACCESS THE TUNNEL

 

Thanks for everything!

Recommended Solution
  1  
  1  
#8
Options
7 Reply
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 00:52:22

Hi @asda123 

Thanks for posting in our business forum.

I recommend you take a look at this guide:

How to Configure WireGuard VPN on Omada Controller

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 04:14:05

  @Clive_A 

Hey Clive,

 

Thanks for reaching back to me, is there any benefit to using the controller than the Web GUI? From that article you mentioned, I noticed that the Router WG interface and the PC WG interface are completely different, is this intended? Was this the thing I've missed out? I'll give it a go anyway, just keep in mind that my goal is to create the tunnnel between my home router and my remote Ax55 router and only forward traffic for the LANs.

 

Thanks! Will update in a couple of hours.

  0  
  0  
#3
Options
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 05:37:42

Hi @asda123 

Thanks for posting in our business forum.

asda123 wrote

  @Clive_A 

Hey Clive,

 

Thanks for reaching back to me, is there any benefit to using the controller than the Web GUI? From that article you mentioned, I noticed that the Router WG interface and the PC WG interface are completely different, is this intended? Was this the thing I've missed out? I'll give it a go anyway, just keep in mind that my goal is to create the tunnnel between my home router and my remote Ax55 router and only forward traffic for the LANs.

 

Thanks! Will update in a couple of hours.

The interface does not really matter. What matters is how you configure it. 0.0.0.0/24 is not really correct. You wanna examine your two rotuers and refer to the guide for the conventional config.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 05:51:15 - last edited 2024-09-19 05:55:25

  @Clive_A 

 

Hey again,

 

Tried with different WG interfaces IP, the tunnel doesn't go up.

 

Managed to get to work and have access to both routers and based on that guide I did the following:

 

R1 WG: 10.10.10.1

Allowed address: 192.168.100.1/24 (R2 subnet)

 

R2 WG: 10.10.10.2

Allowed address: 192.168.0.1/24 (R1 subnet)

 

In this situation, I cannot ping from R1 > R2 or R1 > R2 subnet.

 

 

If I change the configuration on R2 from what was above to:

 

R2 WG: 10.10.10.2

Allowed address: 0.0.0.0/0

 

I can ping from R1 > R2 anywhere, but only from R1. When I try to ping from the R1 subnet:

 

 

Also this is what I'm seeing on the R2 subnet from Wireshark:

 

 

Red is the R1 router, blue is the R1 subnet.

 

What exactly am I missing out?

 

L.E. 

This is the routing table from R2. (TUNS is OpenVPN)

And here is from R1

  0  
  0  
#5
Options
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 05:56:05

Hi @asda123 

Thanks for posting in our business forum.

asda123 wrote

  @Clive_A 

 

Hey again,

 

Tried with different WG interfaces IP, the tunnel doesn't go up.

 

Managed to get to work and have access to both routers and based on that guide I did the following:

 

R1 WG: 10.10.10.1

Allowed address: 192.168.100.1/24 (R2 subnet)

 

R2 WG: 10.10.10.2

Allowed address: 192.168.0.1/24 (R1 subnet)

 

In this situation, I cannot ping from R1 > R2 or R1 > R2 subnet.

 

 

If I change the configuration on R2 from what was above to:

 

R2 WG: 10.10.10.2

Allowed address: 0.0.0.0/0

 

I can ping from R1 > R2 anywhere, but only from R1. When I try to ping from the R1 subnet:

 

 

 

Also this is what I'm seeing on the R2 subnet from Wireshark:

 

 

 

Red is the R1 router, blue is the R1 subnet.

 

What exactly am I missing out?

Ping the default gateway instead of a client. You know how Windows firewall or antivirus works. So, if you want to verify if the tunnel is working or not, the most basic technique is to ping the gateway to verify if the tunnel is up or not.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#6
Options
Re:ER707-M2 and AX55 Wireguard VPN issue
2024-09-19 06:07:20
Already disabled FW in both clients. The thing I noticed is that from R1 I can ping R2 subnet, but not the R2 WG interface, why would that be?
  0  
  0  
#7
Options
Re:ER707-M2 and AX55 Wireguard VPN issue-Solution
2024-09-19 06:19:38 - last edited 2024-09-19 06:52:25

So the documentation for the AX55 is dumb.

 

The tunnel works but I had to enable a specific client on the AX55 to access the VPN -.-"

 

That's why I couldn't establish the connection.

 

All good, for the ones that will come across the same thing, MAKE SURE THAT AFTER YOU SET UP THE TUNNEL YOU ENABLE A DEVICE TO ACCESS THE TUNNEL

 

Thanks for everything!

Recommended Solution
  1  
  1  
#8
Options