Wire guard VPN routing to VLAN missing

Wire guard VPN routing to VLAN missing

Wire guard VPN routing to VLAN missing
Wire guard VPN routing to VLAN missing
Yesterday
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.6 rel.12399

Hi everyone,

I am trying to set up a "Teleportation VLAN" where a specific VLAN routes out to a commercial WireGuard VPN (KeepSolid), but the rest of my network stays on the main WAN.

I have the ER8411 Gateway managed by the Omada Controller OC 300. I have successfully established the WireGuard tunnel (Handshake is good, data flows).

The Problem:

I cannot find a way to apply a Policy Route to this WireGuard interface.

Transmission > Routing > Policy Routing: The "WAN" dropdown only lists physical ports (WAN/LAN1, SFP+, etc.), not the VPN interface.

VPN > VPN Policy: The "VPN Type" dropdown lists OpenVPN, IPsec, L2TP, and PPTP, but WireGuard is missing.

What I have tried:

If I set AllowedIPs = 0.0.0.0/0 in the Peer settings, the router installs a global default route and forces ALL my traffic (Main LAN included) through the VPN.

If I change 0.0.0.0/0 to my VLAN subnet, the VPN connects but no traffic flows through it because there is no policy directing VLAN 60 to use it and it seems backwards. The only solution I see is to use OpenVPN or other VPN type.

Question:

Is there any way on the current ER8411 firmware to use WireGuard as an interface in Policy Routing? Or is WireGuard on Omada currently strictly "All-or-Nothing" via the AllowedIPs field?

Thanks!

  0      
  0      
#1
Options
2 Reply
Re:Wire guard VPN routing to VLAN missing
23 hours ago

  @Obsanity 

 

There is no policy route on either wireguard or openvpn yet. So with wireguard it is all or nothing when the router is a pure client, openvpn has a bit more choice, you can choose source network, you can also edit ovpn to add push route if you don't want all traffic in the vpn tunnel.

 

  0  
  0  
#2
Options
Re:Wire guard VPN routing to VLAN missing
20 hours ago

Hi  @Obsanity 

To help assist and streamline the identification of the behavior, we recommend sending an email to forumsupport.usa@tp-link.com with the following information:

 

Subject: [Forum Escalation][ID 855968]

Forum Nickname: 

Thread URL:  https://community.tp-link.com/en/business/forum/topic/855968

Model&Version: 

Description:

Any Other Relevant Information (Logs, Config Files, Images, etc.): 

 

Once sent, a ticket will be created in our support system, and a member of the team will follow up to gather more information or troubleshoot a cause.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#3
Options