Configuring ER605 with Wireguard VPN doesn't work

Configuring ER605 with Wireguard VPN doesn't work

Configuring ER605 with Wireguard VPN doesn't work
Configuring ER605 with Wireguard VPN doesn't work
Yesterday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.5 Build 20240522 Rel.75860

Hi.

 

I'm trying to configure the gateway ER605 as VPN Server using Wireguard profile.

I describe the scenery:

  • Local network: 192.168.1.0
  • Router local IP: 192.168.1.1
  • Mode: PPPoe (Movistar router on bridge mode)
  • No CGNAT from ISP, I can open ports without problems.


With a laptop from anywhere (another network, with fiber or 5G connection) I need to connect to this device, configuring Wireguard.

I describe the configuration done:

  • ER605
    • VPN -> Wireguard -> Wireguard:
      • Name: Wireguard
      • MTU: 1420 (default)
      • Listen port: 51820 (default)
      • Private key (default)
      • Public key (example: ****1144)
      • Local IP Address: 10.10.10.100
  • Laptop
    • Omada VPN
      • Profile name: Wireguard
      • Type: Wireguard VPN
      • IP: (WAN IP): 51820
      • PublicKey: (example: ****1144)
      • IP Address: 10.10.10.2/32
      • Port (empty)
      • (Generate)
      • PrivateKey (default)
      • PublicKey: (example: ****1155)
      • DNS: 8.8.8.8
      • Full traffic enabled
  • ER605:
    • VPN -> Wireguard -> Peers:
      • Interface: Wireguard
      • PublicKey: (example: ****1155)
      • Endpoint (empty)
      • Endpoint port (empty)
      • Allowed Address: 10.10.10.0/24 or 10.10.10.2/32
      • Preshared key (empty)
      • Persistent Keepalive (default: 25)

 

Also, openned port 51820 in Transmission -> NAT -> Virtual Servers:

  • Name: VPN
  • Interface: WAN
  • External port: 51820
  • Internal port: 51820
  • Internal Server IP: 192.168.1.1
  • Protocol: ALL

 

When I try to connect from laptop side, the application shows that is connected; and from ER605 side, in VPN -> Wireguard -> Peers shows traffic movement (Rx bytes, Tx bytes, Rx packets, Tx packets increase; and last hanshake updates) but if I try to connect to devices inside 192.168.1.X (192.168.1.1 the router, 192.168.1.105 a NAS) they don't load. Seems like the connect has been done correctly, but it doesn't have permission to access to local network.

 

Am I missing some steps? Maybe firewall rules configuration? Or internal routing?

Thanks in advance.

  0      
  0      
#1
Options
3 Reply
Re:Configuring ER605 with Wireguard VPN doesn't work
Yesterday

Hi  @eineltec 

Thanks for posting in our business forum.

May I ask what is your WAN IP on the ER605? Is it a public IP?

Is it possible to show us the configuration and tunnel page with screenshots?

By the way, you can try to update the firmware for your ER605 V2 with this link and see if the issue still persists or not.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:Configuring ER605 with Wireguard VPN doesn't work
22 hours ago

Hi @Hank21 

I have made progress, and now could work using laptop trying to connect with the ER605.

 

I updated firmware to the last version, but this wasn't the problem.

I didn't add that under WAN2 port (first LAN port configured as second WAN) I have connected a MR6400 4G router as auxiliar internet conection.

But it wasn't well configured, so inbound traffic was received successfully, but outbound traffic wasn't sent well.

 

I disabled second WAN adapter and now works well, but as I told, with my laptop.

I tried with Omada VPN application and Wireguard application, both working well (but I chose to Wireguard for DDNS compatibility and android application).

 

With laptop works well, with one mobile phone (Samsung Note9) works well, but with other phones (S23 Ultra, S25) it's not working, and don't know why.

Same configuration (only changing publickey association and IP address of the device) and ER605 only receives 2-3 Rx/Tx packets, and pages aren't loading.

 

With the another phone works well, more packages are sent and the pages are loading OK.

 

I'm totally sure it's mobile configuration, but what type of configuration may affect?

  0  
  0  
#3
Options
Re:Configuring ER605 with Wireguard VPN doesn't work
11 hours ago

Hi  @eineltec 

Considering your Wireguard VPN cannot work well with some Samsung phones, so please try to check the firmware updates on the clients and try to setup a new VPN for them to connect for test.

If the issue still persists, please provide the following information:

1. OS version of your Samsung phones which cannot work well with the VPN.

2. The VPN configuration screenshots of the working and not-working phone for reference.

 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#4
Options