What's new

RT-AX88U Pro Wireguard

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

StephanK

Occasional Visitor
I run Asuswrt-Merlin 3004.388.8 2 on a RT-AX86U Pro.

I work with the OpenVPN client to generate a VPN WiFI network.

Now I want to switch to Wireguard, as it is faster. I have set up Wireguard on my remote router in Europe (Fritzbox 6690 Cable). I can perfectly connect from my desktop and my mobile phone. Great speed.

The Asus says connected, but does not transmit any data.

Any idea where to start troubleshooting?
 
The Asus says connected, but does not transmit any data.
Have you setup VPN Director Rule for the WireGuard client to route the traffic or clients to the WireGuard tunnel?
 
No. Thanks for pointing that out. I put in a route for 0.0.0.0/0 and it works!

Double speed going from OpenVPN to WireGuard!
 
Last edited:
One more question: OpenVPN hat the option to push ALL traffic through the VPN including DNS. This is how Freebee for example detects if you use a VPN.

Accept DNS Configuration Strict
Redirect Internet traffic through tunnel Yes(all)

How do I do this with WireGuard?
 
How do I do this with WireGuard?
Wireguard does not have all different options that ovpn does. This was a design choice.

It only works with vpndirector rules - this is the most flexible way altough requires the user to add the rules in vpndirector.

It will only use "Exclusive" dns redirect when needed - that is using firewall to redirect dns.


. I put in a route for 0.0.0.0/0 and it works!
Using RemoteIP: 0.0.0.0/0 without specifying Local IP may be a bad idea for various reasons. And vice versa.

If you want to redirect internet data, put your lan in Local IP (I.e 192.168.50.0/24) and leave Remote IP blank. You should also add another rule for your router in Local IP (192.168.50.1) to use WAN. This is to make sure you can still access webui if killswitch kicks in amongst other reasons.

If you have a specific set of ips you always want to reach over the tunnel (like site-2-site, like 192.168.51.0/24) you could add these in Remote IP and leave Local IP blank so even the router itself could access these.
 
Thank you, that makes sense.

In regards to RemoteIP: 0.0.0.0/0: yes, that is how I have it on my Notebook installation. The Asus only serves my streaming devices and is configures from the WAN side, as it is behind my Fios router. It only make a foreign country network for these devices.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top