Conditional Routing Wireguard
Hi,
I need to route the entire traffic from a few clients through a wireguard tunnel.
I asked 2023 for that feature and implementation was planned for Q1 2024.
Can someone confirm that it is possible nowadays?
https://community.tp-link.com/en/business/forum/topic/621198
https://community.tp-link.com/en/business/forum/topic/621148
Thank you
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi @bsz
Thanks for posting in our business forum.
When configuringthe Wireguard VPN, the Allowed IP on the client side should be 0.0.0.0/0, and the Allowed IP on the server side should be the WireGuard Interface IP of the peer.
For detailed configuration, please refer to the How to configure WireGuard VPN on Omada Router in Standalone mode
• The above guide uses Windows WireGuard software as an example for the client. If using the official Omada VPN software, there is no Allowed IP option, so just simply enable Full Tunnel.
• The configuration is the same for the client using Omada gateway. Please note that the Allowed IP on the client side being proxied should be all zeros, while the Allowed IP on the server side providing the proxy should be the WireGuard Interface IP (i.e., the Local IP Address).
- Copy Link
- Report Inappropriate Content
thank you for the answer, but that is not the requirement.
there is no Wireguard on any client computer.
the tunnel is setup on a gateway (site-to-site)
i want to route SOME clients (all traffic) through the tunnel
by a rule on the gateway.
i want to route SOME clients (only necessary traffic) through the tunnel
by a rule on the gateway.
it is doable on a a unifi (Unifi Gateway Policy-Based-Routing)
- Copy Link
- Report Inappropriate Content
Hi @bsz
Thanks for your valuable reply.
There is no policy route on Wireguard. So with Wireguard it is all or nothing when the router is a pure client, while OpenVPN has a bit more choice, you can choose source network which is allowed to access the Internet via VPN tunnel.
For more information about OpenVPN, you can refer to this guide.
- Copy Link
- Report Inappropriate Content
@Hank21 So for my case, i am using Surfshark. But instead of openvpn, i want to try wireguard. My case is that in my network, i only want 1 of the vlan to use wireguard, rest use the normal WAN. I know its not supported for now but in the future will it be supporeted?
- Copy Link
- Report Inappropriate Content
