Router as Wireguard client blocks LAN reachability to same Wireguard server the router is connected to

18 Months have passed since I opened this ticket, and yet it is not solved in the stable branch of GL-X750 Spitz

I’m running

**Version:** 3.217
**Date Compiled:** 2023-05-08 04:37:48 (UTC+02:00)
**SHA256:** ff062ea6f5f528e7825c690c3bcbf4f768606e944ec5e155cd78567b44fdb22b

Snapshot is:

**Version:** 4.3.7
**Date Compiled:** 2024-01-08 21:26:53 (UTC+01:00)
**SHA256:** 46753b69003255c0c3f144b22587b915beafe9365f0fd53d74a6681dbc7f67e8

On the firmware download page for GL-X750 Spitz (GL.iNet download center) this line appears in the changelog of

**Version:** 3.105
**Date Modified:** 2020-12-14 10:54:07 (UTC+01:00)
**SHA256:** 56641430e71795d9e2d80e7736478d4a5d2a121a4a351cdec3888bbb97a5015d

Important bug fix


Fixed the problem that the client of the router cannot access the address of the Wireguard server when using Wireguard client

So you are aware of this since at least 2020-12-14, and today 2024-1-10 your stable branch still blocks secure VPN connection of LAN clients to WireGuard server when router is connected as client to same WireGuard server.

Very disappointed

Yes, that bug is already fixed.
What’s your wireguard server, if it’s a gl.inet one, have you enabled “Allow Remote Access LAN”?

remote server is BSD firewall running on VPS with public IP. Wg network is 10.1.0.0/16. It has dozens of connected peers. Each peer has allowed IP /32, firewall does the forwarding within the WG network only (split tunnel).

local gatway is is GL-X750 Spitz running Version: 3.217. It is 10.1.5.50/16 inside the VPN.

local LAN client is Ubuntu desktop. It is 10.1.6.7/16 inside the VPN.

when I turn on wg client on GL-X750 Spitz, firewall can reach 10.1.5.50 but not 10.1.6.7. When I turn off wg client on GL-X750 Spitz, firewall can reach 10.1.6.7 but not 10.1.5.50.

when I turn on wg client on GL-X750 Spitz, local LAN client (ubuntu desktop) can reach any IP on the Internet EXCEPT the public IP (outside the VPN tunnel!) of the remote wg server.

If I flash the very same GL-X750 Spitz with OpenWRT stable and use the very same wg config applied to original firmware, it works as expected and both LAN client and gateway router can connect to same wg server at the same time, as public IP routing toward the wg server is not disrupted by the gateway.

Please try x750 4.3.7 firmware… GL.iNet download center

won’t switch from stable to snapshot to fix a routing problem. I need a stable solution. I’m not a tester but a customer.

I already have a working solution based on custom firmware derived from OpenWRT. It does work, it passes my lab tests, but it’s not the official stable solution from GL.iNet staff, and I well now how modem needs tuning to be stable, and it is.

I’m losing confidence that betting on GL.iNet software was the right thing to do

4.3.7 is the stable firmware. Please give me a final chance.

I now see you moved Version: 4.3.7 from snapshot to stable channel

I’m more than happy to test it now.

1 Like

so its not my config then, it was the routers all along, i have been trying to set this up for 3 days

1 Like