WAN access stops working once I connect via WireGuard

WAN access stops working once I connect via WireGuard

WAN access stops working once I connect via WireGuard
WAN access stops working once I connect via WireGuard
Saturday
Model: ER707-M2  
Hardware Version: V1
Firmware Version: 1.3.0

Hello Everyone,

 

I have an issue with Wireguard. It's similar case (or at least seems so) as in this topic: https://community.tp-link.com/en/business/forum/topic/610050

however I do not know what's the actual solution and if the OP actually had the same exact problem as I did.

 

The idea is that I want any and all traffic to pass through the VPN, as if I've been connecting from (say) home.

 

Once I connect, I have no trouble reaching local hardware. But when I try to browse the net, it doesn't work at all.

Moreover - if I connect to a jumphost (be it Windows or Linux based, doesn't matter), the jumphost itself has now trouble reaching the outside world.

 

I can't open any network site, ping times out, and if I try to use my local DNS, even the name resolution fails, as the DNS itself can't reach outside world (I don't have and don't want to cache entries for hours or days, that's not the point here and it still won't fix anything besides the name resolution).

 

I thought that when I set the allowed IPs to 0.0.0.0/0, then everything will work as planned but it clearly doesn't.

 

It is as if the whole traffic is being routed back to WG subnet instead of going where it's supposed to (WAN in that case), but that's just a wild guess.

 

Can anyone help me out? Am I doing something wrong or it's like that by design (and if so, why?).

 

 

ps. congratulations on the regexp words filtering - if one sentence in post ends in " T " and the next begins with " IT'S " it's interpreted as female feeding organs. Flabbergasting.

  0      
  0      
#1
Options
4 Reply
Re:WAN access stops working once I connect via WireGuard
Monday

  @meowing_parrot 

Thank you for your post.
Could you please share screenshots of your current WireGuard VPN configuration on the gateway and of the VPN-client settings? While configuring, make sure the IP range you assign does not overlap or conflict with the subnet already used on your LAN.

When you say that local hardware remains reachable after the VPN connects, do you mean the VPN client can successfully ping devices on the gateway’s LAN, and only Internet access is failing?

  0  
  0  
#2
Options
Re:WAN access stops working once I connect via WireGuard
Monday - last edited Monday

  @Ethan-TP 

Here you go:

 

As for the question - correct. Once connected, local devices can be pinged, RDP'd or SSH'd to. Can't say the same about the WAN.

Also, if I connect (say SSH) into a server that's reachable and try to reach WAN that way, it also doesn't work.

  0  
  0  
#3
Options
Re:WAN access stops working once I connect via WireGuard
Yesterday

  @meowing_parrot 

What about your VPN-client settings—how did you configure them?
Also, what does the LAN-side setup look like on your local devices?

  0  
  0  
#4
Options
Re:WAN access stops working once I connect via WireGuard
Yesterday

  @Ethan-TP 

 

Here's a screencap from phone's WG app.

Going from the top:
Name / Pubkey / Address / DNS servers / MTU

//

Pubkey / Allowed IPs / Endpoint / Connection keepalive

 

 

As for the LAN devices, I'm not sure what kind of information would you like to get. Overall most things are present in 192.168.1.0/24 subnet, have 24 mask set, use default gateway & two local DNS servers. Nothing fancy. Unless this is about something else, then please clarify, so I may provide the information you need.

  0  
  0  
#5
Options