Sat Apr 27, 2024 6:24 pm
(1) Ether4 has an IP address and a Pool, but MISSING is dhcp server and dhcp-server network ?????
(2) I gather you want all bridge traffic to go out internet on VPS.
(3) On this note I would get rid of the static DNS setting and modify:
from:
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=10.2.0.254 name=router.lan
TO:
/ip dns
set allow-remote-requests=yes servers=1.1.1.1,8.8.8.8
(4) ROUTING RULE has a problem look at the *400
From:
/routing rule
add action=lookup disabled=no src-address=10.2.0.0/24 table=*400
TO:
/routing rule
add action=lookup-only-in-table Min-Prefix=0 table=main comment="ensures local lan traffic does not go out tunnel"
add action=lookup src-address=10.2.0.0/24 table=wg comment="force bridge traffic out tunnel"
(5) YOu have no firewall rules to speak of, are you behind an upstream router?
(6) Why are you mangling, also note the same *400 error.
(7) What type of VPS is provided a wireguard VPS or something else........
If you are not able to set the allowed IPs on the VPS to include the subnet of the bridge, then your wireguard sourcenat rule is a good idea........
(8) Routes look incomplete/wrong. Assuming ether1 is WAN and there is no mention of default route so you need at least two routes. The route to the VPS is not required.
/ip route
add dst-address=0.0.0.0/0 gateway=gatewayIP table=main
add dst-address=0.0.0.0/0 gateway=wireguard1 table=wg