Hello,
I'm trying to port forward from my VPN provider into the router's port itself. From the tcpdump I see that incoming connection but the response is routed through wan.
config redirect
option target 'DNAT'
option name 'vpn-pf'
option src 'wg'
option src_dport '12345'
option dest_port '51822'
list proto 'udp'
option dest_ip '192.168.2.1'
I read few old topics in the forum but they mostly have iptables command and I guess it's not the case in the latest builds (nft, I guess)
11:44:35.637256 IP [mobile device].5929 > 100.70.70.39.12345: UDP, length 148
11:44:35.648444 IP 192.168.0.125.51822 > [mobile device].5929: UDP, length 92
11:44:35.648494 IP 192.168.0.125.51822 > [mobile device].5929: UDP, length 92
I've enabled "NAT loopback" and tried with internal and external IP under port forwarding. No change.
a set of rules/routes for each internet connection.
Usually the pbr option works fine for the most. mwan3 is an overkill for your case. The set of rule/route is the simplest, however uci rules cannot match port, hence it needs to be done with fwmark.
I do alread have pbr running. But I don’t know the IP of the incoming connection. How do I set it up that it can route back the traffic correctly? Without disturbing the other pbr rules.
I thought it would be as simple as normal port forwarding. Shouldn't this already take care of the return traffic?
No, you'd have to set that the reply interface should match the inbound interface (one example). It could probably be done my port, IP, etc too. I personally don't use PBR (I manually make the rules), so others can give PBR examples to you.
Otherwise, the default metric/order of the gateways takes priority.
I think we are saying the same thing.
You are trying to connect to the wg server from the vpn. Responses are going out of wan interface. You need to have a rule to send the responses of the wg server via the vpn.
Then you can fix the above rule by removing the source IP address. Leave only the source port for the matching criteria. In case it doesn't work, post the output mentioned at the bottom of the page for getting help.