[Feature request] Replace Wireguard with AmneziaWG

Hello,

Nice document!
Welcome to GL.iNet Forum!

Is the link to the "official GL.iNet download page" incorrect?
It should be GL.iNet download center

Thank you!
I bought this model solely for native openwrt firmware to support AmneziaWG.

But does anyone know how to set this up on a GL-AXT1800? I have 2 of these.

Worked, but config import from file not worked! Nice job!!!

Thanks for greeting.

Yes you are right it should be GL.iNet download center

Looks like I can't edit the post

Hello, Bruce!!!
Will this instruction work on the new router state 7?! I want to buy

OK, I edited the correct link.

It seems that these packages only support MT3000 with op24 firmware.

1 Like

I would get a device that supports native openwrt firmware. But it may be possible to install the package if the Target Platform is supported. You can attempt to compile your own packages using the github action.

In my case for AXT1800 is running on openwrt 21.02 and I believe the minimum openwrt version required is 23.05

AXT1800 v4.8.0, the op version is 23.05.

1 Like

Any ETA for version 4.9.0?

This version is a bit unstable. I had issues staying connected to wifi. But I may try it on my spare to test to see if I can setup awg

May I know what WiFi issue did you encounter in Slate AX v4.8.0?

Are 2.4GHz and 5GHz WiFi the same SSID? If yes, please change to different.

If no luck, please PM me the WiFi issue syslog.

We are currently working hard for v4.8.0 firmware.

The v4.9.0 is under pre-research, but the expected time is not sure.
It is after all functions are completed to pre-research, and move to develop, then we may estimate the approximate release time.

1 Like

After installing the packages in step 2, I had to reboot the MT-3000 (Beryl). This step is not mentioned/missing in the guide. Otherwise, the protocol "AmneziaWG VPN" was not selectable / did not appear in the dropdown list for Step 4.1 "Create new interface".

In step 5, I was able to manually enter a firewall zone name like "awg_zone". The web interface did mention "(create)" next to it, but did not offer to configure the zone as mentioned (e.g. for setting Input/Output/Forward to accept). So I had to manually change to Network/Firewall later and modify the corresponding entry.

Then my problem was:
The AWG connection to the peer seems to be OK and working. Checking Status/AmneziaWG I see traffic received and transmitted on the interface including last handshake timestamp. However, I couldn't manage to establish a connection from the laptop (connected via wifi to the MT-3000) to the internet via the AmneziaWG interface. I could not get it working with firmware version 4.6.6 and also not with version 4.7.5, which I tried in addition.

I want to have all LAN/wifi traffic of the MT-3000 exclusively routed via the AmneziaWG interface, without having any traffic bypassing the VPN (for usage in a restricted country).

So -- while I prepared this for a post to ask how to set it up, I managed to configure it (hopefully properly). Please find here some screenshots of the required firewall configuration (based on version 4.7.5):

AND BY THE WAY -- with 4.7.5, LuCI is on port 8080 --> http://192.168.8.1:8080/cgi-bin/luci

HTH somebody else running into the same issue.

Have fun!

2 Likes

Hello, I buy be3600 (state 7 router)!!! How to install amnesiawg on this?!

Thats work for me


But the main thing why it didn't work before was missing default route via awg interface
Don't forget to switch it on NETWORK-->INTERFACES-->AWG interface-->peers-->Route Allowed IPs
apply and restart the interface

How did you compile packages for the custom OpenWRT version from official firmware?

@bruce Please, use specifically the latest AmneziaWG 1.5 version, as there were vulnerabilities in the 1.0 which made it susceptible to blocking. This is extremely important, as 1.0 is going to be useless very soon and is already being blocked in a lot of places.

Thanks for the suggestions.
Will forward to PM team.

1 Like

The instructions there are a bit confuse...

"...You will have to configure Amnezia using LUCI web interface, but once configured and installed, you can continue using full power on GL.iNET interface (including VPN settings)..."

There is no instructions about how to install it or how to configure it.