@alzhao any thoughts? we actually purchased a second unit, and went to install it on another network, and are having the exact same issue. There is very little to do to set up the VPN so we arent sure were we could be going wrong.
The odd part is, for both devices, even though it isnt the main router, somehow when someone connects to the wireguard VPN, it brings the entire network to a standstill. any device connected to the router sitting behind the VPN is still unable to connect, and just sits there spinning forever and timing out.
Logs from the second device.
"Thu Apr 20 15:37:34 2023 daemon.notice netifd: Interface ‘wgserver’ is setting up now
Thu Apr 20 15:37:34 2023 daemon.notice netifd: Interface ‘wgserver’ is now up
Thu Apr 20 15:37:34 2023 daemon.notice netifd: Network device ‘wgserver’ link is up
Thu Apr 20 15:37:35 2023 user.notice mwan3[9105]: Execute ifup event on interface wgserver (wgserver)
Thu Apr 20 15:37:35 2023 user.notice mwan3[9105]: Starting tracker on interface wgserver (wgserver)
Thu Apr 20 15:37:36 2023 user.notice firewall: Reloading firewall due to ifup of wgserver (wgserver)
Thu Apr 20 15:40:32 2023 daemon.notice netifd: Network device ‘wgserver’ link is down
Thu Apr 20 15:40:32 2023 user.notice mwan3[16912]: Execute ifdown event on interface wgserver (unknown)
Thu Apr 20 15:40:32 2023 daemon.notice netifd: Interface ‘wgserver’ is now down
Thu Apr 20 15:40:32 2023 user.notice firewall: Reloading firewall due to ifdown of wgserver ()
Thu Apr 20 15:40:48 2023 daemon.notice netifd: Interface ‘wgserver’ is setting up now
Thu Apr 20 15:40:48 2023 daemon.notice netifd: Interface ‘wgserver’ is now up
Thu Apr 20 15:40:48 2023 daemon.notice netifd: Network device ‘wgserver’ link is up
Thu Apr 20 15:40:48 2023 user.notice mwan3[18315]: Execute ifup event on interface wgserver (wgserver)
Thu Apr 20 15:40:48 2023 user.notice mwan3[18315]: Starting tracker on interface wgserver (wgserver)
Thu Apr 20 15:40:50 2023 user.notice firewall: Reloading firewall due to ifup of wgserver (wgserver)
"
Also to clarify both devices are MT3000, and both networks which the wireguard VPN doesnt work have different modems and routers, so I would be surprised if its a specific network config.
They are both home networks with nothing special about them.
In your first post, the screenshot shows that the tunnel has been established successfully. Therefore, it could be a routing issue on the client side.
Could you please provide the output of the following command:
ip route
In addition, please provide a screenshot of the WireGuard client status page. As @SmurfonToast mentioned, are you using Auto Detect mode? Generally, a global proxy is a more common use case.
@alzhao - I will confirm and make sure they are running 4.2.1
@SmurfonToast - I dont think so, as I am not running in repeater mode, and I think autodetect is already selected, but I will confirm.
@hansome - Where do I run that command from? should I SSH onto the device and run it from there?
I will confirm the auto detect mode when I get home. Here is a pic of the client status:
Ok. there was an update, but confirmed router is on 4.2.2
MTU is set to 1380
Proxy is set to auto detect
This is the result of IP route when wireguard server is off:
10.0.0.0/24 dev eth0 proto kernel scope link src 10.0.0.10
10.8.0.0/24 dev ovpnserver proto static scope link
192.168.8.0/24 dev br-lan proto kernel scope link src 192.168.8.1
192.168.9.0/24 dev br-guest proto kernel scope link src 192.168.9.1 linkdown
and when wireguard server is on, when client is connected:
default via 10.0.0.1 dev eth0 proto static src 10.0.0.10
10.0.0.0/24 dev eth0 proto kernel scope link src 10.0.0.10
10.0.0.0/24 dev wgserver proto kernel scope link src 10.0.0.1
10.8.0.0/24 dev ovpnserver proto static scope link
192.168.8.0/24 dev br-lan proto kernel scope link src 192.168.8.1
192.168.9.0/24 dev br-guest proto kernel scope link src 192.168.9.1 linkdown
Also I am using the wireguard phone app to try and connect.
Same as before though as soon as I connect with my phone via cell connection, the entire network coming out of the MT3000 in the house comes to a halt for some reason
I fount that your wan IP range is the same as wirguard tunnel IP. Please change wireguard server IP range and export and import to client.
Also please use global proxy mode instead of auto detect mode at client side.
I don’t know what to tell you man, I can’t access the LAN or any filesystem on the LAN while connected to the wireguard server and Yes Samba is enabled too.