Following my last post about how to change LAN to WAN, I have attempted to install Wireguard on the TL-WR902AC v3. Wifi works fine but unfortunately the VPN is still showing my home location and not that of the UK. I notice that on the VPN Interface there is no RX Pkts so I assume that this is at least one of my problems.
Hope someone can help. Thanks in advance. Below are a few screen shots of my setup:
Your network configuration is invalid since your LAN and WAN are on the same subnet. It appears that you have an upstream router, so you need to change your LAN address to a different subnet (and using a /16 is entirely necessary... I always recommend sticking to /24 for ease of use unless you have a reason to do otherwise).
The WR902AC must be in router mode and clients must be connected through it in order for this to work. So your LAN and WAN must be unique networks.
You can use generally any RFC1918 range you like, but since you have a WAN in the 192.168.1.0/24 network, you must not use anything that overlaps with existing upstream network. You could use 192.168.10.0/24 or 10.0.4.0/24, just as some examples.
Convention (but not required) is that the router (your WR902AC) will take the first address (i.e. 192.168.10.1 or 10.0.4.1 in my examples). A subnet mask of 255.255.255.0 (or /24 in the CIDR notation) will set your network such that it is all contained within the last octet with a range of 1-254.
So I have to change the WR902AC IPv4 LAN address interface to something like 192.168.2.1? The trouble is I can't get access to LuCI using my browsers unless I use 192.168.1.2. I've tried 192.168.2.1, 192.168.100.1, 192.168.10.1, for example, but I can't get my web browsers to open LuCI, it always defaults to my Livebox. Ethernet is OK but not the browser. I've tried turning off the Livebox wifi, clearing browser cache, and incognito mode but with no luck.
Ok, so based on this diagram, the WR902AC will serve as another router. This will create at double-NAT situation when the VPN isn't running, but usually that isn't much of an issue. When the VPN is running, it will function to tunnel your traffic through to your VPN provider.
To make this work, you will indeed need the WAN and LAN to be on different subnets. When properly configured, client devices will connect via Wifi directly to the WR902AC and they will be connected to the internet via the VPN connection.
If you need to administer the WR902AC from the WAN/upstream side (i.e. from the LAN on your Livebox modem/router), you can add a traffic rule to allow port 80 (LuCI web interface) and/or 22 (ssh) from the WAN [NOTE: This is okay when the upstream network is a LAN that you control; never do this if the WAN is the internet or any network that you cannot trust]. Otherwise, you can always access the admin features by connecting via wifi to the WR902AC.
I changed the LAN to 10.0.4.0 (I don't know how to make it 10.0.4.0/24) and now I can access LuCI via wifi! However there are still no no RX Pkts. Here are the new screen shots:
Use 10.0.4.1 as the address and 255.255.255.0 as the subnet mask.
Delete the IPv4 gateway address and let it auto populate. Delete the custom DNS servers entry, too.
Once that is done, reboot your WR902AC and check to see if you have internet access via the WR902AC.
Here is the new screen shot (I did a new install): The IPv4 gateway address didn't auto populate. And still no RX Pkts (presumably because of the latter? Wifi works ( I can open web pages but couldn't upload these screen shots with OpenWrt).
Thanks for the that. I will need to learn how to edit config files, so please bear with me. I will be using a Macbook. Do you know a good place to start?
I presumably just need to delete 51820 from the wg set up?
You can often edit many of the config files via the web interface (LuCI), but this is not always true for certain things. If you want to manually edit your config files, you can simply ssh into the router and make changes, you can use UCI commands, or directly edit the files using nano or vi (text editors). You can also copy the files to your Mac using scp, edit them using a text editor on the Mac, and then scp them back into place.
Make a backup before you make manual changes so that you can restore from that backup in the event that you have to reset your entire router to recover from a mistake.
Thanks for the pointers. I eventually worked out how to edit! In the end I used vi. However, I decoupled the VPN interface in the hope that I could install openssh-sftp-server so that I could used Cyberduck. When I reconnected nothing seemed to work and so I did another clean install (I forgot to do a backup).
Once up and running, I did your config edits and now the wifi seems to work better and I can download with OpenWrt connected. However, there are still no RX Pkts and the VPN doesn't connect to the UK.