Hi Quan, WireGuard is a layer 3 tunnel device, so AllowedIPs should probably be a different IP than endpoint unless you've set up some policy based routing. Also, you'll need to configure the devices with ip-addr too -- what were your commands there? Regards, Jason