Need help using wireguard with 3 subnets

I'm running openwrt and wireguard on a NanoPi R2S as my router (location A / lan=192.168.200.0/24).
I use VLAN-3 (jail=192.168.203.0/24) to separate my IoT devices. So they do not have access to the internet.

Same config is running at my parents home (location B). Only difference are the ip ranges (lan=192.168.100.0/24 jail=192.168.103.0/24)

From any device within lan (192.168.200.0/24) it is possible to access a device in jail (192.168.203.0/24). Works as expected.

Both locations are connected via wireguard, and I'm able to access every device in the remote "lan" and vice versa.

But when I connect to location A as roadwarrior, I'm not able to access any device in jail or in location B.
Of course I can ping the NanoPi itself via 192.168.200.1 or 192.168.203.1.
So I assume that "allowed ip's" at roadwarrior is correct. -> "192.168.203.0/24, 192.168.200.0/24, 192.168.100.0/24"

I did not understand what is the difference between a device connected directly to lan and a device connected via wireguard as "wg0" and "lan" are 2 devices in "lan"

When looking in luci -> interfaces -> wg0 -> peer I found this:
"Required. IP addresses and prefixes that this peer is allowed to use inside the tunnel. Usually the peer's tunnel IP addresses and the networks the peer routes through the tunnel."
But when adding "192.168.203.0/24" to allowed IPs, the route entry changes from "192.168.203.0/24 dev br-jail scope link src 192.168.203.1" to "192.168.203.0/24 dev wg0 scope link"
As a result nobody can connect to a device in "jail" anymore. So this information is very confusing.

I guess that I need a magic route entry to get access to my VLAN-3 and the 192.168.100.0/24 net as roadwarrior connected via wireguard.
Please help ...

/etc/config/network

config interface 'loopback'                                                                                                                                                                      
        option ifname 'lo'                                                                                                                                                                       
        option proto 'static'                                                                                                                                                                    
        option ipaddr '127.0.0.1'                                                                                                                                                                
        option netmask '255.0.0.0'                                                                                                                                                               
                                                                                                                                                                                                 
config globals 'globals'                                                                                                                                                                         
        option ula_prefix 'fdc0:a8:c8::/48'                                                                                                                                                      
                                                                                                                                                                                                 
config interface 'lan'                                                                                                                                                                           
        option type 'bridge'                                                                                                                                                                     
        option ifname 'eth1'                                                                                                                                                                     
        option proto 'static'                                                                                                                                                                    
        option netmask '255.255.255.0'                                                                                                                                                           
        option ip6assign '60'                                                                                                                                                                    
        option ipaddr '192.168.200.1'                                                                                                                                                            
                                                                                                                                                                                                 
config device 'lan_eth1_dev'                                                                                                                                                                     
        option name 'eth1'                                                                                                                                                                       
        option macaddr '32:F4:CA:5A:5A:d5'                                                                                                                                                       
                                                                                                                                                                                                 
config interface 'wan'                                                                                                                                                                           
        option ifname 'eth0'                                                                                                                                                                     
        option proto 'dhcp'                                                                                                                                                                      
                                                                                                                                                                                                 
config interface 'wan6'                                                                                                                                                                          
        option ifname 'eth0'                                                                                                                                                                     
        option proto 'dhcpv6'                                                                                                                                                                    
                                                                                                                                                                                                 
config interface 'jail'                                                                                                                                                                          
        option type 'bridge'                                                                                                                                                                     
        option ifname 'eth1.3'                                                                                                                                                                   
        option proto 'static'                                                                                                                                                                    
        option ipaddr '192.168.203.1'                                                                                                                                                            
        option netmask '255.255.255.0'                                                                                                                                                           
        option ip6assign '64'                                                                                                                                                                    
                                                                                                                                                                                                 
config interface 'wg0'                                                                                                                                                                           
        option proto 'wireguard'
        option listen_port '22222'                                                                                                                                                               
        list addresses '172.16.0.200/32'                                                                                                                                                         
        option dns_metric '50'                                                                                                                                                                   
                                                                                                                                                                                                 
config wireguard_wg0                                                                                                                                                                             
        option description 'site2site'                                                                                                                                                             
        option endpoint_host 'site2site.dynv6.net'                                                                                                                                               
        option endpoint_port '22122'                                                                                                                                                             
        option persistent_keepalive '25'                                                                                                                                                         
        option route_allowed_ips '1'                                                                                                                                                             
        list allowed_ips '172.16.0.100/32'                                                                                                                                                       
        list allowed_ips '192.168.100.0/24'                                                                                                                                                      
                                                                                                                                                                                                 
config wireguard_wg0                                                                                                                                                                             
        option description 'roadwarrior'                                                                                                                                                             
        option route_allowed_ips '1'                                                                                                                                                             
        list allowed_ips '172.16.0.201/32'                                                                                                                                                       
                                                                                                                                                                                                 
config interface 'LTE'                                                                                                                                                                           
        option proto 'dhcp'                                                                                                                                                                      
        option ifname 'eth2'

/etc/config/firewall

config defaults                                                                                                                                                                                  
        option syn_flood '1'                                                                                                                                                                     
        option input 'ACCEPT'                                                                                                                                                                    
        option output 'ACCEPT'                                                                                                                                                                   
        option forward 'REJECT'                                                                                                                                                                  
                                                                                                                                                                                                 
config zone                                                                                                                                                                                      
        option name 'lan'                                                                                                                                                                        
        option input 'ACCEPT'                                                                                                                                                                    
        option output 'ACCEPT'                                                                                                                                                                   
        option forward 'ACCEPT'                                                                                                                                                                  
        list network 'lan'                                                                                                                                                                       
        list network 'wg0'                                                                                                                                                                       
                                                                                                                                                                                                 
config zone                                                                                                                                                                                      
        option name 'wan'                                                                                                                                                                        
        option input 'REJECT'                                                                                                                                                                    
        option output 'ACCEPT'                                                                                                                                                                   
        option forward 'REJECT'                                                                                                                                                                  
        option masq '1'                                                                                                                                                                          
        option mtu_fix '1'                                                                                                                                                                       
        list network 'wan'                                                                                                                                                                       
        list network 'wan6'                                                                                                                                                                      
        list network 'LTE'                                                                                                                                                                       
                                                                                                                                                                                                 
config forwarding                                                                                                                                                                                
        option src 'lan'                                                                                                                                                                         
        option dest 'wan'                                                                                                                                                                        
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-DHCP-Renew'                                                                                                                                                           
        option src 'wan'                                                                                                                                                                         
        option proto 'udp'                                                                                                                                                                       
        option dest_port '68'                                                                                                                                                                    
        option target 'ACCEPT'                                                                                                                                                                   
        option family 'ipv4'                                                                                                                                                                     
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option src 'wan'                                                                                                                                                                         
        option proto 'icmp'                                                                                                                                                                      
        option family 'ipv4'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
        list icmp_type 'echo-request'                                                                                                                                                            
        option name 'Allow-ICMPv4'                                                                                                                                                               
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-IGMP'                                                                                                                                                                 
        option src 'wan'                                                                                                                                                                         
        option proto 'igmp'                                                                                                                                                                      
        option family 'ipv4'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-DHCPv6'                                                                                                                                                               
        option src 'wan'                                                                                                                                                                         
        option proto 'udp'                                                                                                                                                                       
        option src_ip 'fc00::/6'                                                                                                                                                                 
        option dest_ip 'fc00::/6'                                                                                                                                                                
        option dest_port '546'                                                                                                                                                                   
        option family 'ipv6'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-MLD'                                                                                                                                                                  
        option src 'wan'                                                                                                                                                                         
        option proto 'icmp'                                                                                                                                                                      
        option src_ip 'fe80::/10'                                                                                                                                                                
        list icmp_type '130/0'                                                                                                                                                                   
        list icmp_type '131/0'                                                                                                                                                                   
        list icmp_type '132/0'                                                                                                                                                                   
        list icmp_type '143/0'                                                                                                                                                                   
        option family 'ipv6'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-ICMPv6-Input'                                                                                                                                                         
        option src 'wan'                                                                                                                                                                         
        option proto 'icmp'                                                                                                                                                                      
        list icmp_type 'echo-request'                                                                                                                                                            
        list icmp_type 'echo-reply'                                                                                                                                                              
        list icmp_type 'destination-unreachable'                                                                                                                                                 
        list icmp_type 'packet-too-big'                                                                                                                                                          
        list icmp_type 'time-exceeded'                                                                                                                                                           
        list icmp_type 'bad-header'                                                                                                                                                              
        list icmp_type 'unknown-header-type'                                                                                                                                                     
        list icmp_type 'router-solicitation'                                                                                                                                                     
        list icmp_type 'neighbour-solicitation'                                                                                                                                                  
        list icmp_type 'router-advertisement'                                                                                                                                                    
        list icmp_type 'neighbour-advertisement'                                                                                                                                                 
        option limit '1000/sec'                                                                                                                                                                  
        option family 'ipv6'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-Wireguard-Input'                                                                                                                                                      
        list proto 'udp'                                                                                                                                                                         
        option src 'wan'                                                                                                                                                                         
        option target 'ACCEPT'                                                                                                                                                                   
        option dest_port '22222'                                                                                                                                                                 
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Allow-ICMPv6-Forward'                                                                                                                                                       
        option src 'wan'                                                                                                                                                                         
        option dest '*'                                                                                                                                                                          
        option proto 'icmp'                                                                                                                                                                      
        list icmp_type 'echo-request'                                                                                                                                                            
        list icmp_type 'echo-reply'                                                                                                                                                              
        list icmp_type 'destination-unreachable'                                                                                                                                                 
        list icmp_type 'packet-too-big'                                                                                                                                                          
        list icmp_type 'time-exceeded'                                                                                                                                                           
        list icmp_type 'bad-header'                                                                                                                                                              
        list icmp_type 'unknown-header-type'                                                                                                                                                     
        option limit '1000/sec'                                                                                                                                                                  
        option family 'ipv6'                                                                                                                                                                     
        option target 'ACCEPT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Support-UDP-Traceroute'                                                                                                                                                     
        option src 'wan'                                                                                                                                                                         
        option dest_port '33434:33689'                                                                                                                                                           
        option proto 'udp'                                                                                                                                                                       
        option family 'ipv4'                                                                                                                                                                     
        option target 'REJECT'                                                                                                                                                                   
        option enabled '0'                                                                                                                                                                       
                                                                                                                                                                                                 
config include                                                                                                                                                                                   
        option path '/etc/firewall.user'                                                                                                                                                         
                                                                                                                                                                                                 
config zone                                                                                                                                                                                      
        option name 'jail'                                                                                                                                                                       
        option input 'ACCEPT'                                                                                                                                                                    
        option output 'ACCEPT'                                                                                                                                                                   
        option forward 'REJECT'                                                                                                                                                                  
        list network 'jail'                                                                                                                                                                      
                                                                                                                                                                                                 
config forwarding                                                                                                                                                                                
        option src 'lan'                                                                                                                                                                         
        option dest 'jail'                                                                                                                                                                       
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Reject NTP to WAN'                                                                                                                                                          
        option src 'lan'                                                                                                                                                                         
        option dest 'wan'                                                                                                                                                                        
        option dest_port '123'                                                                                                                                                                   
        option target 'REJECT'                                                                                                                                                                   
                                                                                                                                                                                                 
config rule                                                                                                                                                                                      
        option name 'Drop SMB Stuff'                                                                                                                                                             
        option src 'lan'                                                                                                                                                                         
        option dest 'wan'                                                                                                                                                                        
        option dest_port '137-139 445'                                                                                                                                                           
        option target 'DROP'                                                                                                                                                                     

config rule                                                                                                                                                                                      
        option name 'Drop Jail 2 WAN'                                                                                                                                                            
        option src 'jail'                                                                                                                                                                        
        option dest 'wan'                                                                                                                                                                        
        option target 'DROP'                                                                                                                                                                     

You have two choices. You can either separate the VPN interface into it's own firewall zone, turn on masquerading, allow forwarding to LAN and vice versa. Or you can add the IP of your roadwarrior device to the allowed_ips on the device at location B.

2 Likes