ER8411 V1 Wireguard stopped working after firmware upgrade to 1.3.1

Hello,
I have ER8411 V1 and OC200.
After a firmware upgrade from 1.2.3 to 1.3.1, Wiregaurd VPN is now completly broken.
I have rx and tx on the android Wiregaurd app but I cannot access any of my local ips and no internet access when Wiregaurd is turned on!!!
Does anyone else having this issue?
It was working juts fine when I was on firmware 1.2.3.
I can post my configs for the Wiregaurd VPN if anyone has a clue.
Thanks!!!
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
It's hassle-free to upgrade, you downgrade without going stand-alone. You connect with SSH and downgrade with the roll-back command.
- Copy Link
- Report Inappropriate Content
MR.S wrote
It's hassle-free to upgrade, you downgrade without going stand-alone. You connect with SSH and downgrade with the roll-back command.
MR.S,
How do you SSH into the router (do you ssh from cmd or use a program)?
What is the syntax with cmd?
I use putty with IP and using the user:admin and password:pass that is on the ER8411 but when I type enable I don't get the list like that, do you know the reason?
I tried roll-back in standalone mode and it worked. Didn't know I can do it not being in standalone mode (crap)!!!
Thanks!!!
- Copy Link
- Report Inappropriate Content
yes you are in the right place you type enable and then roll-back, but roll-back is a new command in the 1.3.1 firmware so you will not see it until you have upgraded.
type ? to see commands
- Copy Link
- Report Inappropriate Content
MR.S wrote
yes you are in the right place you type enable and then roll-back, but roll-back is a new command in the 1.3.1 firmware so you will not see it until you have upgraded.
type ? to see commands
Got it thanks!!!
Oh man, this makes it so much easier not going into standalone mode for the downgrade!!!
Cheers!
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
did you disable NAT on Wireguard and OpenVPN? when it comes to OpenVPN, ACL works so if you have any ACL then try disabling this
- Copy Link
- Report Inappropriate Content
MR.S wrote
did you disable NAT on Wireguard and OpenVPN? when it comes to OpenVPN, ACL works so if you have any ACL then try disabling this
Yep all NAT for WG and OVP are disbaled. I deleted ACL for the OpenVPN.
Should I change anything in the firewall:
I will do another reboot to see how it goes, thanks!!!
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
MR.S wrote
Yep, confirmed both are working now on the 1.3.1 Firmware, the main issue was the NAT and port forwadring (for anyone having this issue make sure to disable NAT for WG and OpenVPN ports!!!) and since I have dynamic IP, it took sometime for the cloudflare DDNS script (on my UNRAID server) to update my WAN IP address.
Thanks @MR.S and everyone else for the help on this matter!!!
Please request the TP-Link team to implement a way to restrict WG access (WAN only, LAN only, or both) on the upcoming Firmware!!!
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 801
Replies: 25
Voters 0
No one has voted for it yet.