Brume2 - WireGuard VPN Server Only for Existing LAN

Looking to setup a Brume2 as a Wireguard VPN server, so I can remotely access my home LAN. I have an existing router that for other reasons I need to keep in place. I have an Pi currently running Wireguard that I’m looking to replace with the Brume2.

What is the best approach (aside from replacing my current router) for setting this up?

Thanks in advance!

Best approach is always

  1. Connect Brume 2’s WAN to your main wifi’s LAN
  2. Set up port forward from main router’s 51820 to Brume 2’s IP
  3. Enable Wireguard server.
1 Like

not sure this is the right thread for this but tried to not to create another new post

I have brome 2 connect to Telstra smart modem gen 2 (Australia ISP)

I tried to set up port forward from the smart modem to Brume 2 (that is running wireguard server, try not to use openvpn for obvious reason)

I need help to set up the port forward

Question 1 - which service do I choose , web server or vpn? and what port from Wan to Lan?

but if vpn, there is no option for wireguard , so I have to force to use openvpn?

What is in the list? I think you just need to try. Maybe it does not matter. It is just shortcut to fill the values.

Here is what you should do:

Name: Any name you want to set
Protocol: UDP. This is a must
WAN Port: 51820
LAN Port: 51820
Desitination IP: find the IP address of Brume2’s WAN interface.

oh, it does not work on TCP ?

Wireguard work on UDP, not TCP.

Choose openvpn if you need TCP.

1 Like

Thanks for the solution, it worked for me!

Is it now possible to access the Brume2 from my existing network or is this only possible via the LAN port of the Brume 2?

You need to open ports on Brume 2.

Or you can access via the Wireguard tunnel.

If you’ve done what was mentioned higher in this thread, you should be able to access the Brume 2 from outside your network once you’ve connected your device to the Wireguard VPN. Once you do that, you should be able to use the IP address assigned to the Brume 2 on your home LAN to connect to the Brume 2 for management (this is one reason I like to setup a static DHCP IP address for the Brume 2 in my router’s configuration).

@alzhao
@pie

Thanks for the answer, but unfortunately it doesn’t work

which ports should I open?
I have the setup like in the post above.
It does not work with or without Wireguard Tunnel activated

My WAN IP from Brume 2 is 192.168.1.149 and that from Brume 2 is 192.168.9.1. I tried both IP addresses.

I also tried a static IP from network 192.168.1.0 to 192.168.9.0, but that doesn’t work either

You shouldn’t have to forward any ports if you’re connected to the Brume’s Wireguard server already. Check the Wireguard server configuration and enable these two settings if they’re disabled:

  1. Remote Access LAN
  2. IP Masquerading (not sure if this is necessary, but I have it enabled and the scenario you’re looking for works for me)
1 Like

@pie
thanks for the reply

The Remote Access LAN option was deactivated and now it works.

Before your tip, I once opened port 80 on the firewall and then I got to the Brume 2 from the LAN (192.168.1.149), but neither works via Wireguard

2 Likes

I set up my Brume2 this week and could not get 2-way traffic to work for a while. I ended up having to add a firewall rule to the Brume2 to allow my local LAN to connect to the remote LAN. Once I set that up, bidirectional traffic started working.