ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup

ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup

ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
2024-08-16 06:27:09 - last edited 2024-08-16 06:57:33
Model: ER706W-4G  
Hardware Version: V1
Firmware Version: ER706W-4G_V1_1_0 1.20240723.67170(4555)

At initial bootup , the ER706W-4G doesn't always initiate outgoing traffic on the wireguard vpn interface until I manually go into the wireguard peer in the web ui and click disable and then enable.

 

Edit: This is with keepalive enabled and an endpoint configured

Edit2: I figured out a workaround by setting the secondary ntp server to the internal ip of a server at the other end of the wireguard vpn

  0      
  0      
#1
Options
4 Reply
Re:ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
2024-08-16 06:46:15

  @staples1347 

 

I think this only happens if you have 0.0.0.0/0 as destination. if you try this in controller mode, you have to readopt the router after every boot.

the rumors say that Policy route comes in Omada version 5.15/5.16 with associated router firmware

 

 

  0  
  0  
#2
Options
Re:ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
2024-08-16 23:41:37

  @MR.S 

 

At the moment the Peer endpoint is set to the public ip of the remote wireguard server, Allowed Address is set to 10.17.0.0/18 , and I have Persistent Keepalive set to 14.  Also, I am running the router in standalone mode.  It's possible this is normal for wireguard as on full Linux servers, I normally also setup OSPF to go along with the vpn which keeps traffic flowing in both directions on a regular basis, but OSPF on this router doesn't seem to be showing the wireguard interface as an option.

  0  
  0  
#3
Options
Re:ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
2024-08-19 01:49:24

Hi @staples1347 

Thanks for posting in our business forum.

OSPF and RIP are now only working with the GRE VPN.

The rest of the VPN types do not support it.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. Don't be a lazy asker. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#4
Options
Re:ER706W-4G: Bug: Wireguard doesn't always initiate traffic at initial bootup
2024-08-20 00:03:47 - last edited 2024-08-20 00:04:14

  @staples1347 

I just setup a client to server Wireguard vpn on Linux and can confirm with persistent keepalive set to 14 seconds , the wireguard "client" sends keepalive packets every 14 seconds even if the interface isn't sending any packets so it looks like this isn't functioning on the TP-Link.  Note: To determine that the TP-Link wasn't sending keepalive packets, I ran tcpdump on the router that the TP-Link's wan interface was connected to in addition to running "wg show" on the wireguard server.

  0  
  0  
#5
Options