After finally figuring out how to get WireGuard site-to-site setup nicely here, I saw multiple threads about performance issues & tested myself to find out... I have the same performance problems. Until it can be fixed, I'm trying to get the same config I had setup with WireGuard, done with OpenVPN instead & would appreciate any feedback as I've been having some trouble. I tried following this guide as well for some reference, but it's not working quite right & I'm not that familiar with the routing configs (& the guide itself isn't that clear).
What I'm trying to do is here:
Some assumptions & a question:
Something doesn't seem quite right, at best I get unidirectional success (if I turn on Create NAT on Tunnel for Site #2) but not bidirectional. Would anyone have any insight? Help is much appreciated!
What I'm trying to do is here:
Code:
Site #1:
AX88U Asus Merlin 388.1
LAN: 192.168.25.1
Client will use VPN to access: LAN only (change to both if needed, not needed for my case)
VPN Subnet/Netmask: 192.168.20.0 / 255.255.255.0
Advertise DNS to clients: Yes
Manage Client-Specific Options: Yes
Allow client <-> Client: Yes
Allowed clients: <commonname1> / 192.168.25.0 / 255.255.255.0 / Yes (Push)
Custom configuration:
push "route 192.168.25.0 255.255.255.0"
route 192.168.50.0 255.255.255.0
reneg-sec 432000
Site #2:
AX88U Asus Merlin 388.1
LAN: 192.168.50.1
VPN Client: 10.6.0.2/32
OpenVPN Client Create NAT on Tunnel: No
OpenVPN Client Inbound Firewall: Allow
Accept DNS configuration: Relaxed
Redirect Internet traffic through tunnel: No
Some assumptions & a question:
- Since the server side is pushing Site #1's LAN subnet to the OpenVPN client, the client side doesn't need any routing set up in its Custom configuration setting.
- The server side needs routing set up on its side so that other clients of the server's LAN can access Site #2's LAN subnet
- The config itself has client <> client options, so assuming I don't need to add a route for 192.168.20.0
- Do I need to do any VPN Director routing rules on Site #2?
Something doesn't seem quite right, at best I get unidirectional success (if I turn on Create NAT on Tunnel for Site #2) but not bidirectional. Would anyone have any insight? Help is much appreciated!
Last edited: