Hi,
after few tests I'm still dealing with lost of wireguard interface.
The button stop is active but I don't see it in "ifconfig".
Do you think "Force link" option could help ?
please find my config below:
root@OpenWrt:~# ubus call system board
{
"kernel": "5.10.176",
"hostname": "OpenWrt",
"system": "Atheros AR9132 rev 2",
"model": "TP-Link TL-WR1043ND v1",
"board_name": "tplink,tl-wr1043nd-v1",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "22.03.5",
"revision": "r20134-5f15225c1e",
"target": "ath79/generic",
"description": "OpenWrt 22.03.5 r20134-5f15225c1e"
}
}
Only available after "wg1" interface restart:
root@OpenWrt:~# wg show
interface: wg1
public key: xxx=
private key: (hidden)
listening port: 64646
peer: xxx=
preshared key: (hidden)
allowed ips: 192.168.3.0/24, 192.168.2.0/24
NETWORK:
config interface 'loopback'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
option device 'lo'
config globals 'globals'
option ula_prefix 'fda2:74cf:9d87::/48'
config interface 'lan'
option proto 'static'
option netmask '255.255.255.0'
option ip6assign '60'
option ipaddr '192.168.2.254'
option device 'br-lan'
config interface 'wan'
option proto 'static'
option netmask '255.255.255.0'
option ipaddr '192.168.xx.xx'
option gateway '192.168.xx.xx'
option device 'eth0.2'
list dns '192.168.88.88'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option ports '1 2 3 4 5t'
config switch_vlan
option device 'switch0'
option vlan '2'
option ports '0 5t'
config device
option name 'br-lan'
option type 'bridge'
list ports 'eth0.1'
config interface 'wg1'
option proto 'wireguard'
option listen_port '64646'
option private_key 'xxx='
list addresses '192.168.3.1/24'
config wireguard_wg1
option description 'OpenWRT-Acer-Eliott'
option public_key 'xxx='
option preshared_key 'xxx='
list allowed_ips '192.168.3.2/24'
list allowed_ips '192.168.2.30/24'
option route_allowed_ips '1'
FIREWALL:
config defaults
option input 'ACCEPT'
option output 'ACCEPT'
option synflood_protect '1'
option forward 'REJECT'
config zone
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option name 'ZONE0'
list network 'lan'
list network 'wg1'
config zone
option name 'wan'
option masq '1'
option mtu_fix '1'
option input 'REJECT'
option forward 'REJECT'
option output 'ACCEPT'
list network 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option proto 'esp'
option target 'ACCEPT'
option dest 'ZONE0'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
option dest 'ZONE0'
config include
option path '/etc/firewall.user'
config forwarding
option dest 'wan'
option src 'ZONE0'
config rule
option name 'Allow-Wireguard-Inbound'
list proto 'udp'
option dest_port 'xxxx'
option target 'ACCEPT'
option src 'wan'
Note: "config redirect" deleted.
Note 2: I'll delete everything concerning "3" network, i want to acces to lan aera I don't see the any use to keep 192.168.3.xx:
config interface 'wg1'
option proto 'wireguard'
option listen_port '64646'
option private_key 'xxx='
list addresses '192.168.2.253'
config wireguard_wg1
option description 'OpenWRT-Acer-Eliott'
option public_key 'xxx='
option preshared_key 'xxx='
list allowed_ips '192.168.2.30/24'
option route_allowed_ips '1'
Thank you for help.