Subnet gets inaccessible with Wireguard Peer active

Subnet gets inaccessible with Wireguard Peer active

Subnet gets inaccessible with Wireguard Peer active
Subnet gets inaccessible with Wireguard Peer active
Sunday
Model: ER7412-M2  
Hardware Version:
Firmware Version: 1.2

Hi,

my Computer is hook up to my default Subnet 192.168.1.0/24, VLAN1, IP 192.168.1.100/24.

My NAS is hook up to my Storage Subnet 192.168.65.64/28, VLAN65, IP 192.168.65.67/28.

ACL Rule is set to LAN/LAN Allow all services biderectional. Accessing my NAS is flawlessly possible.

Portforwarding is active for UDP51820 on both ends.

Now i set up a Wireguard Server, IP 192.188.51.1/24. Connect a remote Host, IP 192.188.51.100/24. Allowed Addresses 192.188.51.0/24, 192.168.65.67/28.

Set up the corresponding Peer on the Gateway, Connection established. Under Insights, VPN, Wireguard it shows the Client active, Data going back and forth.

But here comes my Problem.

As soon as the VPN Connection is established, i cannot access the NAS from my computer, neither can the VPN Client. The Gateway on the other hand can still ping the NAS Address without any problems.

The far end site uses a different subnet, 192.168.178.XXX/24, so thats no Problem.

The VPNs Subnet is also unique.

As soon as the VPN is disconnected, everything works again.

No LOG entries whatsoever.

Any suggestions?

(Please excuse my bad english, my native language is german)

  0      
  0      
#1
Options
2 Reply
Re:Subnet gets inaccessible with Wireguard Peer active
Monday

  @LarsW1982 Thank you for your post. I suspect the issue is related to configuration. Please share the VPN configuration and the Peers configuration for me to review. Additionally, are there any routing-related settings within the LAN? Kindly provide the LAN configuration as well.

  0  
  0  
#2
Options
Re:Subnet gets inaccessible with Wireguard Peer active
Monday

  @LarsW1982  Hello, how are you?
I'm from Brazil and I've had a lot of trouble with Wireguard, but I've learned how to use it, so I'll make some changes based on your configuration.

 

Hello, how are you?
I'm from Brazil and I've had a lot of trouble with Wireguard, but I've learned how to use it, so I'll make some changes based on your configuration.

Make the changes according to the ones I made in your text.

 

my Computer is hook up to my default Subnet 192.168.1.0/24, VLAN1, IP 192.168.1.100/24.

My NAS is hook up to my Storage Subnet 192.168.65.64/28, VLAN65, IP 192.168.65.67/28.

ACL Rule is set to LAN/LAN Allow all services biderectional. Accessing my NAS is flawlessly possible.

Portforwarding is active for UDP51820 on both ends.

Now i set up a Wireguard Server, IP 192.188.51.1/32. On the Wireguard server's PEER, you'll allow your remote connection to connect (192.168.188.51.2/32). In general, you do not need to enter allowed addresses if the ENABLE FULL TRAFFIC function is activated. Using the Omada VPN Client. Connect a client remote Host In the IP address field of the Omada VPN client IP 192.188.51.2/32. if the ENABLE FULL TRAFFIC function is not activated, You will have to configure the allowed addresses, which in your explanation are 192.168.1.0/24....192.168.65.64/28.

 

I hope I helped

  0  
  0  
#3
Options