Wireguard Server for Internet redirect on ER605v2

Wireguard Server for Internet redirect on ER605v2

Wireguard Server for Internet redirect on ER605v2
Wireguard Server for Internet redirect on ER605v2
a week ago - last edited a week ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428 Rel.18967

Hi, I have tried to set up a Wireguard server on my ER605 v2 (latest firmware).

I used this post in particular as a guide: https://community.tp-link.com/en/business/forum/topic/610198

I have a Wireguard client on my PC (same thing on mobile, not shown here, but same results).

When I activate the tunnel, I appear to connect. Both the server and the client show a handshake and I see some Tx and Rx bits on both. However nothing happens and the client only appears to get initial bits.

Any suggestion? I am getting crazy here and ready to give up.

Thanks

Client

 

 

  0      
  0      
#1
Options
2 Accepted Solutions
Re:Wireguard Server for Internet redirect on ER605v2-Solution
a week ago - last edited a week ago

  @CaptainNemo 

If you could read a different post regarding this, I don't see the reason why you set both WG routing to 0.0.0.0/0. 

You should understand what it means before you put that in the subnet. It is a parameter that can affect your connection instantly. 

How to Configure WireGuard VPN on Omada Controller

 

This is the error I instantly pick up. 

Recommended Solution
  2  
  2  
#2
Options
Re:Wireguard Server for Internet redirect on ER605v2-Solution
a week ago - last edited a week ago

  @CaptainNemo I find that the primary issue I am dealing with is that I do not have mutually exclusive IP ranges for my peers. As soon as I disable one of the peers, the tunnels work. I still have minor issues I need to tweak but the blocking issue was the overlap of permitted IP ranges. 

Recommended Solution
  0  
  0  
#4
Options
4 Reply
Re:Wireguard Server for Internet redirect on ER605v2-Solution
a week ago - last edited a week ago

  @CaptainNemo 

If you could read a different post regarding this, I don't see the reason why you set both WG routing to 0.0.0.0/0. 

You should understand what it means before you put that in the subnet. It is a parameter that can affect your connection instantly. 

How to Configure WireGuard VPN on Omada Controller

 

This is the error I instantly pick up. 

Recommended Solution
  2  
  2  
#2
Options
Re:Wireguard Server for Internet redirect on ER605v2
a week ago

  @Clive_A  Any chance you can explain a bit better than "you should understand"? I looked at the doc and it's not clear where it should be. Also I have over tunnels set up in that manner, that work. Specifically, where should I have the 0.0.0.0/0 and what should I use in the other instead? Thanks

  0  
  0  
#3
Options
Re:Wireguard Server for Internet redirect on ER605v2-Solution
a week ago - last edited a week ago

  @CaptainNemo I find that the primary issue I am dealing with is that I do not have mutually exclusive IP ranges for my peers. As soon as I disable one of the peers, the tunnels work. I still have minor issues I need to tweak but the blocking issue was the overlap of permitted IP ranges. 

Recommended Solution
  0  
  0  
#4
Options
Re:Wireguard Server for Internet redirect on ER605v2
a week ago

  @CaptainNemo 

CaptainNemo wrote

  @CaptainNemo I find that the primary issue I am dealing with is that I do not have mutually exclusive IP ranges for my peers. As soon as I disable one of the peers, the tunnels work. I still have minor issues I need to tweak but the blocking issue was the overlap of permitted IP ranges. 

This is the downside of the Wireguard.

If you have no experience in the VPN realm before, you don't know what each parameter and option means. 

In that guide, I have listed every term and explained what it is and is used for. 

I hope you can take time to digest this information. 

If you want an easy setup, OVPN would be preferable for a beginner. 

 

In the above pictures you provided, you showed two parts where you input 0.0.0.0/0. You need to understand what traffic direction you want to achieve. The guide explicitly explains what this rule defines and means. It is a matter of the routing. Clearly, you set both peers as 0.0.0.0/0 violates the basic routing mechanism. 

  1  
  1  
#5
Options