Partial access to LAN devices through WireGuard server on Flint-2 (MT6000)

Hi,

I set up a WireGuard server on my MT6000 (Flint 2), with a single client (iPhone, config with the Wireguard app).

Network topology : ISP Router (192.168.1.0/24) LAN port > WAN1 port on Flint 2 in router mode (192.168.8.0/24) > TP-Link Switch > LAN devices

The ISP Router is not in bridge mode (not available), but is set to DHCPv4 off and DMZ to the Flint 2. The ISP Router does have DHCPv6 active.
Two devices on LAN have SMB shares active: one Win10, one Synology NAS

The VPN tunnel is working properly: internet access is done through the tunnel on client without issue.

The problem
Via the tunnel on a LTE connexion, I have no issue reaching the SMB shares from the NAS. However, I cannot connect to the SMB shares on the Win10 machine (from diagnosis on the client, I get a timeout). Both shares are fully accessible when the client is connected directly to their subnet (192.168.8.0/24 through the Flint 2 WiFi)
Both devices were set up similarly (fixed IPv4 in 192.168.8.0/24, the rest left on default), and both have internet access and are fully functional.

I cannot figure out where the difference is to explain the discrepancy (Win10 config perhaps?). Any help or suggestion would be welcome. Please note that I am fresh to networking, so there might be obvious issues I have not explored yet.

Many thanks in advance

Disable the Windows firewall on your Win 10 client and check if you can access the share.
If it works, adjust the firewall to allow connections from your VPN.

1 Like

For the record, I added 10.0.0.0/24 to the SMB-in and NB-Session-In default rules, worked like a charm!
Thanks!

1 Like