Portál AbcLinuxu, 12. května 2025 05:10
***** Mikrotik Router 1 ***** /interface/wireguard add listen-port=13231 name=wireguard1 /interface/wireguard/peers add allowed-address=192.168.1.0/24 endpoint-address=200.200.200.200 endpoint-port=13231 interface=wireguard1 public-key="public-key Mikrotik Router 2" /ip/address add address=10.200.0.1/30 interface=wireguard1 /ip/route add dst-address=192.168.1.0/24 gateway=wireguard1 /ip/firewall/filter add action=accept chain=input dst-port=13231 protocol=udp src-address=200.200.200.200 place-before=1 add action=accept chain=forward dst-address=192.168.0.0/24 src-address=192.168.1.0/24 place-before=1 add action=accept chain=forward dst-address=192.168.1.0/24 src-address=192.168.0.0/24 place-before=1 ***** Mikrotik Router 2 ***** /interface/wireguard add listen-port=13231 name=wireguard1 /interface/wireguard/peers add allowed-address=192.168.0.0/24 endpoint-address=100.100.100.100 endpoint-port=13231 interface=wireguard1 public-key="public-key Mikrotik Router 1" /ip/address add address=10.200.0.2/30 interface=wireguard1 /ip/route add dst-address=192.168.0.0/24 gateway=wireguard1 /ip/firewall/filter add action=accept chain=input dst-port=13231 protocol=udp src-address=100.100.100.100 place-before=1 add action=accept chain=forward dst-address=192.168.1.0/24 src-address=192.168.0.0/24 place-before=1 add action=accept chain=forward dst-address=192.168.0.0/24 src-address=192.168.1.0/24 place-before=1
/ip/address add address=10.200.0.1/30 interface=wireguard1Podle navodu neni IP adresa ktera se pridava verejna, ale lokalni(192.168.0.2). V navodu je hadam chyba a misto 10.255.255.1/30 ma byt 10.1.202.1/30.
Příloha: wireguard.png (35362 bytů)Podle obrazku, bude mit PC/Sever vychozi branu na routeru od ISP => na mikrotik se provoz nikdy nedostane => musis pridat statickou cestu do 192.168.1.0/24 pres 192.168.0.2 a stejne i na druhe strane.
Příloha: wireguard.png (35362 bytů)V obrazku je chyba. Wireguard nevytvari samostatnou tunelovanou sit(OpenVPN) => vnejsi "obal" tunelu nebude 10.200.0.x, ale verejna cast ISP ie. peer1/peer2. 50c
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.