Hi, @Stitch177
Thank you for posting on our business forum.
Please find the complete step-by-step WireGuard configuration guide for your devices below:
- Configuration on ER605 side
1.Go to VPN > WireGuard, then click Add on the right side to create and configure a new WireGuard interface. Specify a name for the interface. If you do not have special configuration requirements, you may leave MTU, Listen Port, Private Key and Public Key at their default settings. For the Local IP Address field, please enter the virtual IP for this WireGuard interface. (You may use any valid IP address here; we recommend choosing an address that is not already in use by any other device on your network.) After filling in all required fields, click OK and copy the generated public key for later use.

2.Next, configure the Peer entry on ER605: Go to VPN > WireGuard, navigate to the Peers section, then click Add to start configuration. For the Public Key field, please enter the public key generated from your TL-WR3602BE. For Allowed Addresses, please enter the LAN IP range of your TL-WR3602BE. For Endpoint, you may enter the WAN IP of your TL-WR3602BE. Click Save to confirm the configuration.

- Configuration on TL-WR3602BE side
1.First, log into the local management interface of your TL-WR3602BE, navigate to Advanced > VPN Server > WireGuard VPN, locate the public key generated on this page, and enter this public key into the Peer configuration of your ER605 (as noted in step 2 of the ER605 configuration above).
2.Next, navigate to VPN Merge > Server List, click Add, then select set manually to fill in the required connection parameters:
For the Private Key and Public Key fields: Please enter the corresponding keys generated from your ER605 side.
For the Address field: Please enter an IP address that does not conflict with your existing local LAN IP range.
For the Allowed IP Addresses field: Please enter the LAN IP range of your ER605.
For the Endpoint Address field: Please enter the WAN IP of your ER605.
For the Port field: You may use any available valid port here.
(For the TL-WR3602BE side, we suggest you‘d better contact our Archer support team to double confirm the configuration if the connection is failed.)
