I hope I am just missing something simple here. I have a OpenWRT router with a Wireguard VPN running, everything routing through the VPN, which is all working fine. I have put a route in place so that any traffic I want to go to the lan that is on the Wan side of my router is routed through my wan not my VPN. It works from the router, but not from connected devices.
So just to be clear:
RouterVPN (192.168.114.1) with VPN
RouterGW (192.168.111.1) which the above routers wan is connected to.
A PC (192.168.114.116)
If I ssh in to RouterVPN I am able to ping 192.168.111.1 If I ping from PC I get "Destination port unreachable"
My routing table looks like this (RouterVPN):
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 0.0.0.0 128.0.0.0 U 0 0 0 WG0
0.0.0.0 192.168.111.1 0.0.0.0 UG 0 0 0 eth1
10.14.0.21 0.0.0.0 255.255.255.255 UH 0 0 0 WG0
78.XXX.XXX.134 192.168.111.1 255.255.255.255 UGH 0 0 0 eth1
128.0.0.0 0.0.0.0 128.0.0.0 U 0 0 0 WG0
192.168.111.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
192.168.114.0 0.0.0.0 255.255.255.0 U 0 0 0 br-lan
WG0 is the VPN interface. eth1 is the WAN interface. br-lan is the LAN interface.
I know all of the Metrics are the same value, but I don't know where on an OpenWRT I can look to change this.
So as far as I can tell it routes just fine when I am on the router, but not on connected devices.
I am fair confident the routes for 192.168.111.0 are coming from the VPN Routing Policy, which has these two policies in it:
Policies Comment, interface and at least one other field are required. Multiple local and remote addresses/devices/domains and ports can be space separated. Placeholders below represent just the format/syntax and will not be used if fields are left blank.
Name Local addresses / devices Local ports Remote addresses / domains Remote ports Interface
tolan 192.168.114.0/24 0-65535 192.168.111.0/24 0-65535 WAN
toVPN 0.0.0.0/0 0-65535 0.0.0.0/0 0-65535 WG0
If someone who know way more about networking with OpenWRT than I do can advise please I would greatly appreciate it.
NOTE: I have remote access to the Router, so I can't try deleting and adding routes, as I will lose connection, I need to be very careful, as I will not have onsite access for months.
Thank you in advance.