Hi all,
I'm looking for some advice on how best to configure a true site-to-site VPN between three offices, all using GL.iNet Flint 2 (MT6000) routers.
Current setup
Site A – Main Office
-
Synology NAS running Synology Active Directory Server
-
Multiple Windows PCs joined to the AD domain
-
Vodafone Gigabite connection connected directly to using PPOE GL.iNet Flint 2 (MT6000)
-
The Flint 2 is currently running as the WireGuard server
-
The Synology NAS, AD, file shares, etc. are all located on the Site A LAN
Site B – Remote Office
-
Vodafone Gigabite connection connected directly to using PPOE to second GL.iNet Flint 2 (MT6000)
-
GL.iNet Flint 2 (MT6000)
-
Flint connects to Site A as a WireGuard client
-
PCs are joined to the AD domain at Site A
-
PCs can log on to the domain, receive Group Policy and access file shares on the Synology NAS over WireGuard
Site C – Remote Office
-
Similar setup to Site B
-
GL.iNet Flint 2 (MT6000)
-
Connects back to Site A using WireGuard
-
PCs access the resources/AD services hosted at Site A
The problem
The WireGuard connections work well for accessing Site A from Sites B and C, but they don't appear to operate as a true routed site-to-site VPN.
For example:
Site B → Site A: Works
Site C → Site A: Works
However:
Site A → Site B: Doesn't work
Site A → Site C: Doesn't work
Site B → Site C: Doesn't work
Site C → Site B: Doesn't work
If I need to access something on the LAN at Site B or C from Site A, I currently have to establish a separate VPN connection directly to that site's GL.iNet router.
What I would ideally like is for all three LANs to be properly routed across WireGuard so that devices can communicate between sites as required.
For example:
Site A LAN ↔ Site B LAN
Site A LAN ↔ Site C LAN
Site B LAN ↔ Site C LAN
Each site has its own separate LAN subnet, so there are no overlapping LAN addresses.
What I've tried
I also tried enabling Site-to-Site VPN through GL.iNet GoodCloud, but I couldn't get this working correctly. In particular, I had problems getting connectivity back to Site A and eventually reverted to my existing WireGuard setup.
Question
What is the recommended way of achieving a proper routed site-to-site configuration with three Flint 2 routers?
Can this be achieved using the existing WireGuard server at Site A by adding the appropriate:
-
Allowed IPs
-
Static routes
-
Firewall/forwarding rules
-
Routes between WireGuard peers
Or would I be better off using GL.iNet's GoodCloud Site-to-Site functionality or another solution entirely?
Ideally, I would like Site A to act as the central/hub site, with Sites B and C connected to it, while still allowing traffic to be routed between all three LANs.
Any advice on the correct GL.iNet/WireGuard configuration would be greatly appreciated.


