Hello,
I have already searched through the forum for this issue, found similiar questions, but I am not seeing where the issue lays.
My setup is the following:
LAN <-> Openwrt router (wireguard server) <-> Internet
Internet <-> Openwrt router (wireguard client) <-> LAN
I have formed successfully a wireguard connection between the client and server. I can ping the wireguard server, and also the lan ip of the wireguard server from inside the client LAN. But I cannot reach any LAN ip behind the server router, from the wireguard client LAN.
Openwrt router (wireguard server):
10.0.0.199 br-lan
10.200.200.1 wg0
Openwrt router (wireguard client):
192.168.8.1 br-lan
10.200.200.2 wg0
Example LAN ip behind server router:
10.0.0.124
Example LAN ip behind client router:
192.168.8.2
I can ping from the LAN behind the client router to wg0 server and also the br-lan ip, both 10.0.0.199 and 10.200.200.1.
wg0 is set in firewall zone lan in the wireguard server router:
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option network 'lan wg0'
I also tried setting this, though it is not neccessary if lan and wg0 are same zone, right,
config forwarding
option dest 'wg0'
option src 'lan'
config forwarding
option dest 'lan'
option src 'wg0'
Problem now I cant reach any client IPs in the lan behind the wireguard server router, from the client router lan.