i just bought a Brume (GL-MV1000) to access to my company via wireguard vpn during covid home office.
Company: 100/40 MBit VDSL - there is a VoIP Gateway (Zyxcel Gateway 400) with integrated modem, WAN Port is not free, so i put GL-MV1000 with “WAN” and “ETHERNET” to the Gigabit LAN Switch in Server Rack
Gateway IP 192.168.2.1 / GL-MV1000 IP 192.168.2.4 , Routing in Gateway to Port 51820
Static Routing Table 10.0.0.2/32 to 192.168.2.4 & 192.168.2.0/32 to 192.168.2.4
Wireguard Server is allowed to connect to local lan, i added " list subnet '192.168.2.0/24" to config file on GL-MV1000.
Client at Home:
Windows 10 64 Bit, newest Wireguard Client:
Can you confirm that both the WAN port and a LAN port on the GL-MV1000 are connected via Ethernet to the same Gigabit LAN switch, so that both WAN and LAN are using the same 192.168.2.xxx subnet? The WAN IP is 192.168.2.4. What is the LAN IP?
The router’s WAN subnet and LAN subnet have to be different in order to do routing. There is no routing when devices are on the same subnet and the devices use ARP to resolve layer 3 IP address to Layer 2 MAC address. Each subnet has to be on a different switch, or on a different VLAN on 1 managed switch, in order to work properly.
I do not have knowledge about the Zyxel Gateway 400 on how you can set up the Brume.
If the Brume WAN port is moved to 192.168.8.1, then it will not have connectivity to the Internet which is on 192.168.2.xxx subnet.
If the Brume LAN port is moved to 192.168.8.1, then it will not have connectivity to the Synology NAS and other servers/devices on 192.168.2.xxx subnet.
Is the HP Aruba switch connected directly to a Zyxel LAN port? I am not clear regarding:
Ideally, the Brume WAN should be connected to the Internet with a Public IP, then the Brume LAN can be connected to the internal network on the 192.168.2.xxx subnet. Alternatively, if the Brume WAN can somehow be connected to the Zyxel with an Private IP that is not on the 192.168.2.xxx subnet, then that should work also. My understanding is that the Zyxel does not have DMZ capability that may have accomplished that.