Im trying to setup a Wireguard Server and Wireguard Client.
2x Slate AX ( GL-AXT-1800) ( Also, have Brume 2 & Mango if needed).
Existing home router: ( TP-Link Archer AX1800 or it can be a Netgear AC1750 R6350).
ISP: Fiber
I already attempted to configure both using a ton of previous threads/walk throughs.
I think I am getting snagged at the port forwarding on the home router or im getting confused on the IP config between the Slate AX’s maybe causing conflict?
Server gets established and green but unable to connect via phone or travel Ax/PC.
Goal: Keep one Slate AX at the house, the other Slate AX comes with me when I travel.
Home Router:
Dynamic IP from ISP
Port Forward: 51820
Port Forward on TCP/UDP then just only UDP.
Ethernet from LAN going to the WAN Port of Slate AX Server.
Static IP assigned for Slate AX Server w/ port forward.
On my WG Server I have IP Masquerading on. VPN Cascading wouldn’t apply unless your WG Server device was itself to be a WG Client to a VPN provider (eg: Mullvad, Nord VPN, Express VPN, etc.).
“Services fr GL” refers to such processes like their DDNS service. My WG Client has IP Masquerading on.
Thank you for that info but im still only getting 150b/3kb up/down.
It shows a green connection but I dont have internet when connecting to the Server Slate.
I am testing from a tmobile/mint cell hotspot to test (& Local coffee shop), I read the lower MTU works on this mint/tmobile carrier better, but tested alot of variations with no change on the speeds.
Since the up/down is virtually non-existent, it seems its still a bad config issue i think.
I recently just changed my Slate Server IPv4 IP to 10.20.0.1. Instead of the 10.0.0.1 and produced new WG profiles and just been tweaking MTU. ( also mocked the above config in regard to IP masq., server vpn cascading etc.
Also, do I need to setup port forward on my Slate AX Server ? Currently I just have port forward on my ISP TP-Link Router–> Slate AX Server but not → Slate AX Client
is there any other config needed on the Slate AX Server itself? Not WG configs and not DDNS(its already enabled).
Is there like a config export I can send to export all my config settings? not sure what the next area to check is.
Thanks!
Also note, when scanning my WAN IP, it says port: open|filtered.
Ive been reading that means it didnt get a response.
any commands i can ssh to get to the bottom of this? plz let me know which commands need to be on the ISP router, Slate AX Server or Slate AX Client. ( also let me know if i should be doing these commands while ON the WireGuard?)
I adjusted the MTU to 1280 on both server and client.
I will adjust the port fwd to another port and try that later today.
I was able to connect on my phone via the WG app and on cell network but I was not able to load any sites or anything. It said 1 device connected on the WG Server dash but the speeds were only 500 bytes down and 20kb up and nothing loaded.
The home network of the ISP router and both slates is a fiber connection and gets 600MB down/up consistently.
Im going to try the local coffee shop again shortly and put the MTUs on both Server/client back to default, which i think is like 1400.
what else should i be doing to try to narrow down what this issue is related to?
So instead of using the TP-Link Router as the ISP router.
I completely removed the TP-link router from the network.
The Slate AX Server is now directly plugged into the wall, which I will use the 5ghz wifi as the home network wifi and run the VPN server as well.
Let me know if this setup may cause any leaks in my VPN IP etc.\
OpenVPN works when I connect and transfers around 20mb down/ 20 mb up - which is alright but the home speeds are around 900MB down and 900MB up. So hopefully can still get the WG VPN to work.
I will continue to test later today on the WG setup without the TP link router.
If the TCP OpenVPN setup works but the UDP Wireguard setup does not, does this point to something specific blocking WG?
Thanks
If you’re using the GL GUI → VPN → WireGuard Server to set things up, all port forwarding is handled for your ‘behind the scenes’.
You should check to make sure your ISP/Public IP/Internet IP allows incoming connections to port 51820… otherwise you’ll never reach the Slate AX WG Server.
Hopefully OP isn’t behind CGNAT. @soudy2, you may need to contact your ISP to find out. Their ‘front facing’ routers could be blocking incoming connections to you Public IP.