Network provider confirmed its Dynamic IP but face issues with VPN setup

HI Team,

my internet provider confirmed its dynamic ip, but its not showing the same in Router panel and find my IP in web site is diffrent.

IP address in admin panel : 192.168.100.X
find my ip in web : IPv4: 189.203.100.XXX

Also I am trying to setup VPN server (wire guard)in Flint 2 and use AX3000 as VPM clinet, I have created they file and uploaded in AX3000 but its not connecting. its how like " The
client is starting, please wait…"

used the below option while creating the server

IPv4 Address : 10.0.0.1/24
Listen Port : 51820
Remote Access LAN is On
IP Masquerading is On

Use DDNS Domain is ON

log for your ref:

Mon Nov 11 13:47:34 2024 user.notice firewall: Reloading firewall due
to ifdown of wgclient ()
Mon Nov 11 13:49:00 2024 daemon.notice netifd: Interface 'wgclient' is now down
Mon Nov 11 13:49:00 2024 user.notice firewall: Reloading firewall due
to ifdown of wgclient ()
Mon Nov 11 16:28:03 2024 daemon.notice netifd: Interface 'wgclient' is
setting up now
Mon Nov 11 16:29:48 2024 user.notice wireguard-debug: USER=root
ifname=wgclient ACTION=REKEY-GIVEUP SHLVL=1 HOME=/
HOTPLUG_TYPE=wireguard LOGNAME=root DEVICENAME= TERM=linux
SUBSYSTEM=wireguard PATH=/usr/sbin:/usr/bin:/sbin:/bin PWD=/
Mon Nov 11 16:29:48 2024 daemon.notice netifd: Interface 'wgclient' is now down
Mon Nov 11 16:29:48 2024 daemon.notice netifd: Interface 'wgclient' is
setting up now
Mon Nov 11 16:29:48 2024 user.notice firewall: Reloading firewall due
to ifdown of wgclient ()
Mon Nov 11 16:31:13 2024 daemon.notice netifd: Interface 'wgclient' is now down
Mon Nov 11 16:31:13 2024 user.notice firewall: Reloading firewall due
to ifdown of wgclient ()
Mon Nov 11 16:39:56 2024 daemon.notice netifd: Interface 'wgclient' is
setting up now

Do you mean your ddns is confirmed by your isp, or your isp confirmed you have a dynamic ip?

It does not tell me in which context it is important, can you elaborate what this public ip is?, is that isps or vpn?

First: can you show the server configuration (please mask the private and public keys and also your external ip, for ddns just limit the subdomain).

Second: i also want to see the client configuration, again please remove any sensitive information.

Third: what is the device connected on your wan?, a other router?

Fourth: how do you verify the ddns obtains your ip correctly?, have you pinged it?

Do you mean your ddns is confirmed by your isp, or your isp confirmed you have a dynamic ip?

My internet service provider(ISP) confirmed it’s dynamic IP

Alright :+1:,

Can you post this info?:

It is needed because i need to have a picture of your network and configuration :slight_smile:

Also another question arise, do you think your internet is behind a cgnat?

Meaning your public ip is shared with more isp consumers?

Because then you have a difficult issue to host a server due to a firewall, only option then is to host a external server, the client however can stay behind a cgnat.

It is worth noting when testing vpn locally the endpoints are not using the external wan ip, but use lan something there can be nat translated or it even doesn't go over wan, this means it doesn't work because you have to allow lan :slight_smile:, atleast that is how it shows for me on the non gl wireguard, it is usefull to have a look to output wg show for the server peer :+1:, you can decide to make a temporary rule for lan.

but it works if you are really remotely, aslong there is not a cgnat involved at the server or another upstream firewall i.e a other upstream router.

Is the IP address obtained by the interface connected to the ISP network a public IP? If not, your router cannot be accessed directly through the public network.

If you have the authority to manage the router where the public IP is located, you can use the public IP to obtain the VPN server service by adding firewall port forwarding.

please find the below info, Thanks

I removed your post because it contains sensitive information.

Please don't post your QR code and follow the advice of @xize11 masking the private and public keys and also your external ip, for ddns just limit the subdomain

1 Like