NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Normanras's avatar
Normanras
Follower
Aug 09, 2021

Wireguard+R8000+VPN Passthrough = half access?

I'm not really looking for a solution (I've already searched all the threads here, support articles, Reddit, blog posts, etc and nothing seemed to work), but more looking for some information about why this is happening. 

 

  • On my father's wifi, an R8000. Upgraded to the latest firmware.
  • At home I have Wireguard running on a DD-WRT (Nighthawk R7000)
  • The VPN works great from other most other wifi networks, public wifi, cellular networks, etc.
  • On this wifi network, I can't access the web UI to any of my home LAN apps or SSH into those machines.
  • I've read all the articles and threads I can find. I've tried the suggestions for DMZ of the VPN, Open NAT, disabling SIP AGL, Ping Internet Port, etc etc, I can't access any web UI for my home server, except one....
  • My DD-wrt router UI. This worked from the start, before changing any of the suggested settings.
  • Note: My router is accessed via a DDNS address.

I can ping all the other machines in my home LAN from the R8000 network, and I can access the UI of my DD-WRT. But my NAS, home automation, etc, doesn't show up in any web-browser. I also can't ssh into any of those machines. 

 

ifconfig shows that I am on the correct subnet for Wireguard and my IP address is correct.

 

It just seems strange that I can ping and see the other home LAN machines, but can't access any of them except my router. If I get off wifi and reactivate the tunnel then everything is back to normal. All ssh, ports, web UIs, etc are accessible as expected. 

 

My only thought is that the R8000 subnet is the same (in numbers and mask) as my home LAN and this is confusing NAT of the R8000 router? That's my only hunch since the DDNS address for my router works, but the IP in the web browser does not. 

 

Let me know if anyone else has experienced this too. Again, I've relegated myself to not messing with my father's router anymore to make all the UIs and SSH's work, but if you did find a solution, that's appreciated! Thanks again.

No RepliesBe the first to reply