Asus RG-58AXU
Merlin FW v3004.388.8_4
Hi, first post after much lurking/searching. I have to believe that this is not an uncommon use case, but no joy so far for Asus Merlin/wireguard.
I have a functional wireguard(server) vpn running in my RG-58AXU w/ one WAN Android client accessing my NVR over cellular data.
Works great. Orders of magnitude(subjectively) faster for this purpose than OpenVPN, which I tested first before trying wireguard. I'd like wireguard a WHOLE lot more with authentication, but that's a different challenge.
I am not using the VPN for any other LAN to WAN traffic.
Is there any way within the Merlin UI to limit incoming/outgoing WAN vpn access to specific LAN resources?
Example(not my actual numbers):
RG-58AXU LAN IP: 192.168.1.1
wireguard port: 56354
NVR on LAN, IP 192.168.1.101:14777
Android wireguard client 10.6.0.10
I need to restrict the wireguard client LAN access to the NVR _only_.
I'm not averse to blocking ALL wireguard traffic except port 14777, if that's doable, but it seems heavy-handed.
I do NOT want to resort to local firewall rules on the other devices on my LAN, etc
If not through the ui, if this can be accomplished w/ a script, etc through SSH, can anyone point me in the direction of some code that could be adapted to my use case?
My iptable kung-fu blows, but I'm very willing to try/learn.
Thanks so much for any help/thoughts.
Merlin FW v3004.388.8_4
Hi, first post after much lurking/searching. I have to believe that this is not an uncommon use case, but no joy so far for Asus Merlin/wireguard.
I have a functional wireguard(server) vpn running in my RG-58AXU w/ one WAN Android client accessing my NVR over cellular data.
Works great. Orders of magnitude(subjectively) faster for this purpose than OpenVPN, which I tested first before trying wireguard. I'd like wireguard a WHOLE lot more with authentication, but that's a different challenge.
I am not using the VPN for any other LAN to WAN traffic.
Is there any way within the Merlin UI to limit incoming/outgoing WAN vpn access to specific LAN resources?
Example(not my actual numbers):
RG-58AXU LAN IP: 192.168.1.1
wireguard port: 56354
NVR on LAN, IP 192.168.1.101:14777
Android wireguard client 10.6.0.10
I need to restrict the wireguard client LAN access to the NVR _only_.
I'm not averse to blocking ALL wireguard traffic except port 14777, if that's doable, but it seems heavy-handed.
I do NOT want to resort to local firewall rules on the other devices on my LAN, etc
If not through the ui, if this can be accomplished w/ a script, etc through SSH, can anyone point me in the direction of some code that could be adapted to my use case?
My iptable kung-fu blows, but I'm very willing to try/learn.
Thanks so much for any help/thoughts.