This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
networking:router:mikrotik_vpn_wg [2023/07/02 10:31] gcooper |
networking:router:mikrotik_vpn_wg [2023/07/10 10:36] (current) gcooper |
||
---|---|---|---|
Line 12: | Line 12: | ||
**Road Warrior HowTo**: https:// | **Road Warrior HowTo**: https:// | ||
+ | |||
+ | **Why WireGuard? | ||
+ | |||
+ | **Enable/ | ||
<note tip>Note that **Windows workstations do not respond to pings by default**, but will if you temporarily disable the firewall. | <note tip>Note that **Windows workstations do not respond to pings by default**, but will if you temporarily disable the firewall. | ||
Line 26: | Line 30: | ||
< | < | ||
- | # perform the next two commands only once | + | # perform the next three commands only once |
+ | |||
+ | # allow wireguard connections to the router - move rule as needed | ||
+ | /ip firewall filter add action=accept chain=input comment=" | ||
+ | protocol=udp place-before=4 | ||
# add a wireguard interface - name is arbitrary - select UDP listen port not blocked by all ISPs | # add a wireguard interface - name is arbitrary - select UDP listen port not blocked by all ISPs | ||
- | # only add/create once | + | /interface wireguard add comment=" |
- | /interface wireguard add comment=" | + | |
# set the address of the wireguard interface - the address is arbitrary | # set the address of the wireguard interface - the address is arbitrary | ||
- | # we use a /24 netmask to include all peers - name must match interface name above | + | # we use a /24 netmask |
- | /ip address add address=172.16.2.1/ | + | # name must match interface name above |
+ | /ip address add address=172.16.2.1/ | ||
# do the following for each remote site | # do the following for each remote site |