Question: If I connect the PC.1 under Opal (have done that just for personal testing, did it even during the last test) then PC.1 pings PC.2 normally. I did that to test if firewall blocked me and it didn’t.
So do I still have to dissable the firewall?
Editing this post to let you know that I took a 6 hour penalty to make a new post…
YES! because the firewall does not block ICMP originating (outbound) from the device’s interface… but if it is coming from outside world (inbound) then it is blocked by default.
You can enable the firewall once the testing is finished and you verify the connectivity in both directions PC1 ↔ PC2.
I said ping the Opal ip from your isp router and pc 1 ! Saying verified it does not mean anything you have messed up your settings on both routers and I need to make sure ICMP (eg ping ) is not being blocked
Honestly this is taking very long post I am not gonna feed you everything you have to learn how to navigate your routers menus - familiarize yourself with the menu and routing and firewall options !
I am quiet sure that the configurations I have given you so far should work UNLESS you have done some weird configurations.
Please note in your last test there was no loss as compared to previous tests! That means the settings I gave were correct but ICMP was dropped by the Opal router! Again from PC1 try to access different services on Synology/pc2 like FTP/WEB/SSH…
IP Address: 192.168.5.0 Gateway: 192.168.1.51 Subnet Mask: 24 (or 255.255.255.0)
In Opal Router:
-Wan zone => Lan (Accept, Accept, Accept) Masquerade ON (because OFF I tried first but could not access the ISP router from PC.2 (nor any other device under my ISP router))
Wireguard works perfectly via Opal (for every device under Opal (PC.2, Synology, mobile phone, etc.)
So shall I leave these setting as they are, or shall I change something?
That’s was a mistake ! Because the Opal router is responsible for this network NOT the ISP! And you can spot the issue from the last screenshots you provided : for example rule no 6 shows that the isp can route traffic to this network through interface br0 whereas the interface is LAN4!!!
Tried it, but the connection is lost if I delete the static route.
Now that I can access synology from PC.1 (via inputing it’s ip), I notice that I cannot access it with SMB (SMB was the way that I used to work). Minor loss now that I cannot, but was nice to have it. (i.e. I could see the synology via my network in win10.