need a hand with WG setup

Dimitar Vassilev dimitar.vassilev at
Tue Aug 27 19:20:37 CEST 2019


I'm trying to establish site to site VPN with 2 OpenWRTs 18.6.4 - linux

my problem is that I cannot get any ping running and cannot reach the
remote tunnel ips.
Below is my setup
# ip r
default via dev eth0.2 proto static src dev eth0.2 proto kernel scope link src via dev eth0.2 proto static dev br-lan proto kernel scope link src dev wgknxvtun0 proto static scope link dev wgknxvrtun0 proto kernel scope link src
216.66.xx.xx via dev eth0.2 proto static

root at OpenWrt:~# wg show
interface: wgknxvtun0
  public key: f6
  private key: (hidden)
  listening port: 51820

peer: ThW
  allowed ips:
  latest handshake: 2 minutes, 15 seconds ago
  transfer: 134.86 KiB received, 121.67 KiB sent
  persistent keepalive: every 25 seconds

  root at OpenWrt:~# wg showconf wgknxvtun0
  ListenPort = 51820
  PrivateKey = xxxx

  PublicKey = Tx
  AllowedIPs =
  Endpoint = 130.204.x.x:51820
  PersistentKeepalive = 25

I've setup a separate FW zone where input, forward and output are default.
Ideas what I'm missing are welcome.

