You are on page 1of 9

WireGuard – RFC https://rickfreyconsulting.

com/wireguard/

WireGuard
This entry was posted in MikroTik on August 21, 2020 by rickfrey1000

WireGuard  is a simple, fast, and modern VPN that utilizes state-of-the-art cryptography. Its aims to be a
better choice than IPSEC or OpenVPN. MikroTik added WireGuard support starting in RouterOS version
7.1beta2. You can connect WireGuard to other MikroTik routers or pretty much any other platform out there
includeing Windows and MacOS. The install clients for other platforms can be found here . Let’s take a look at
a simple installation.

1 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 1: In Router 1 (the one on the left) we’ll create the WireGuard Interface. All you have to do, is give it a
name. It will auto generate the Public and Private Keys on it own.

2 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

3 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 2: Repeat Step 1 for Router 2. In Router 2 (the one on the right) we’ll create the WireGuard Interface. All
you have to do, is give it a name. It will auto generate the Public and Private Keys on it own.

Step 3: Set the Peers on Router 1

4 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 4: Set the Peers on Router 2

5 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 5: Add an address to the WireGuard interface on Router 1. (IP -> Address)

6 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 6: Add an address to the WireGuard interface on Router 2. (IP -> Address)

7 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Step 7: At the time of this writing, there is a bug in Winbox with the Endpoint Port. To set the Endpoint Port,
you must configure it in the CLI on both sides as shown.

8 of 12 12/8/2021, 1:25 AM
WireGuard – RFC https://rickfreyconsulting.com/wireguard/

Finally, you will want to verify connectivity by pinging across from both sides. In this example, it will be the two
10.0.0.0/24 addresses that are assigned to the WireGuard interfaces that you will ping to.

Share this:

     

Like this:

Loading...

 Leave a comment
Your email address will not be published. Required fields are marked *

Comment

9 of 12 12/8/2021, 1:25 AM

You might also like