Dynamic Routing with Wireguard, Optimize your MikroTik network!

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ก.ค. 2024
  • In this video, we'll show you how to set up dynamic routing with Wireguard on MikroTik.
    Wireguard is a awesome new security protocol that allows you to create a secure VPN connection between your routers. We'll show you how to set up dynamic routing with Wireguard on MikroTik, so you can securely route traffic between your devices.
    Wireguard is a great way to protect your privacy and security on your network, and this video will teach you how to set it up on your MikroTik routers!
    👊Thanks for taking time to watch my video. If you could, pressing LIKE and SUBSCRIBING helps more people discover my videos. Feel free to leave a comment for any other topics you would like to see me cover or what your general opinion is of the video.
    🕘Timestamps🕘
    📕00:00 - Introduction
    📕00:38 - Lab Overview
    📕03:09 - Wireguard Setup
    📕10:55 - BGP Setup
    Support the Channel:
    ⭐Become a Patreon: / thenetworkberg
    ⭐Become a TH-cam Member: / @thenetworkberg
    Social Media:
    🌏 / thenetworkberg
    🌏 / bergnetwork
    🌏 / the-network-berg-39451...
    MTCRE Playlist:
    • Free MTCRE RoSv6
    MTCNA Playlist:
    • Free MTCNA RoSv6
    Credits:
    Thumbnail: Created on Canva
    Intro: Created on Canva
    Music by Alumo
    Songs used:
    Dioitic
    Outland 85
    Music by Bensound.com/free-music-for-videos
    • Bensound: "The Elevato...
    Thanks again for watching

ความคิดเห็น • 45

  • @TheNetworkBerg
    @TheNetworkBerg  ปีที่แล้ว +5

    Hey guys, just pinning some useful links that you can use to configure Dynamic Routing with Wireguard on MikroTik (Sorry for some pops in the audio, I only realized after recording that the filter was touching the mic and whenever I would hit the table it would make a very slight pop
    MikroTik WG:
    help.mikrotik.com/docs/display/ROS/WireGuard
    MikroTik BGP:
    help.mikrotik.com/docs/display/ROS/BGP
    MikroTik OSPF:
    help.mikrotik.com/docs/display/ROS/OSPF

  • @drlegende
    @drlegende หลายเดือนก่อน

    This video was awesome and fun to follow. you should consider doing a similar one for pfsense although the concept is very similar. A+ to you.

  • @kresimirpecar4925
    @kresimirpecar4925 ปีที่แล้ว +1

    Always pleasure to see new video 😊

  • @trexx_media
    @trexx_media ปีที่แล้ว +2

    🎉🎉🎉🎉 awaiting for it, GURU JI

  • @kidu2k3
    @kidu2k3 6 หลายเดือนก่อน

    can i like this video twice? :) thx, nice tutorial

  • @DanelSwitalski
    @DanelSwitalski 10 หลายเดือนก่อน

    Hello,
    everything works, ibgp works - it will break
    now i will configure ospf as additional routers
    thanks for the material
    Regards
    Daniel

  • @thefixitgal
    @thefixitgal ปีที่แล้ว

    That was pretty sweet! Using wiregaurd rather than Ipsec seems a more modern method. Also Ive noticed route flapping can occur if you share all routes over the tunnel. Would you be able to address how to mitigate this in a video please

  • @ali0ghanem
    @ali0ghanem ปีที่แล้ว +1

    Wow❤❤❤❤

  • @alimibrahem8120
    @alimibrahem8120 ปีที่แล้ว +1

    you are so elegant man..! i love your video ..⬆

  • @adrianocolombo
    @adrianocolombo 8 หลายเดือนก่อน

    I managed to do this; I can interconnect two cities using a common broadband link and even mirror a private IP block, making the network of both places appear as if it were the same network

  • @CzAerox
    @CzAerox หลายเดือนก่อน

    I wonder what to do, if public wifi is blocking "WG" like blocking UDP or something like that. Even using open ports did not made my device to handshake :/ Mostly airport wifi´s. Btw, thanks for your tutorials!

  • @kopyrta
    @kopyrta ปีที่แล้ว

    Hey. Could you please do a video where you show how to connect 3 locations with EoIP tunnels over IPsec (do not merge them in a hub) and run OSPF on loopback interfaces on each office router? Then configure iBGP from each loopback and make server's traffic exchange via iBGP with even prefix filtering from wherever point you want? I was told this is good approach to connect 3 offices. Or some other approach to rock solid connections between different locations. Many thanks in advance!

  • @mrrtee1343
    @mrrtee1343 ปีที่แล้ว

    Can you make video explain and example for each mangle chain rule and action rule? I want to understand each how it works

  • @Anavllama
    @Anavllama ปีที่แล้ว

    The BGP part was interesting. It seemed l like quite a bit of extra work, and you never noted any potential need for firewall rules. Assuming traffic is coming on the connected routes one would still need some forward chain rules etc. In other words, achieving the same functionality, connecting routers, within wireguard ( allowed IPs, firewall rules, routes if necessary ) on the surface seems actually easier to me. We can also force any subnet through wireguard to use the WAN of another router. Being only a home user, I probably wont need BGP etc, but I think the value must come in economies of scale ( the more complex the connections between routers ) where BGP would really shine. Can you point out some other advantages to the BGP method vice just straight wireguard. Thanks!

  • @imanikabeya3542
    @imanikabeya3542 ปีที่แล้ว +1

    Thanks for this beautiful work sir... God bless you so much, I'd like to ask how did you make this topology with that well designed internet ?

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว +1

      I use an emulator called EVE-NG, the cloud is really just a cloud PNG that hides a couple of routers behind it to act as the internet. But it looks nice ;D!

    • @imanikabeya3542
      @imanikabeya3542 ปีที่แล้ว

      Means you downloaded that cloud PNG and uploaded that in your EVE

    • @imanikabeya3542
      @imanikabeya3542 ปีที่แล้ว

      Yes I Know it's EVE but never seen that cloud in Eve tho 🤣😂

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว +1

      Ahhh yeah, this is another "Pro" feature, it allows you to upload images directly into your topology. Not worth the $$$ if you just want to do this, but it does make labs look a lot nicer.

  • @HeikoRehm
    @HeikoRehm ปีที่แล้ว +1

    I run that with OSPF since a while already. Same way - 0/0 on the WG Allowed nets. Plus a little Route-Filtering. Works neatly and so much more stable than it used to be when I had used SSTP.

  • @johanpingree8072
    @johanpingree8072 3 หลายเดือนก่อน

    I watch your awesome video multiple times to ensure I did not miss a step. Wrote a procedures manual for my setup to have as a handy reference for the topology I have. I have all three routers talking to each other and each router can get to the others LAN. iBGP is working and reflecting the routes. I threw in a road warrior which can connect and see all the networks distributed via iBGP. HOWEVER, my LAN clients (on the hub router), for example my desktop, cannot ping the other LAN addresses across the routers, it can ping the tunnel addresses on both sides of the tunnel, but again, not past the tunnel endpoints. This leads me to believe it has something to do with iBGP. I have gone through the settings over a dozen times and still cannot figure out why my local network clients cannot see the other LANs. Can you offer up any pointers? Thanks!

  • @Randomcallity
    @Randomcallity 2 หลายเดือนก่อน

    Awesome stuff. What software do you use for lab simulation?

    • @TheNetworkBerg
      @TheNetworkBerg  2 หลายเดือนก่อน

      It's called EVE-NG a network emulator similar to GNS3

    • @Randomcallity
      @Randomcallity 2 หลายเดือนก่อน

      @@TheNetworkBerg Thanks a lot.

  • @DanelSwitalski
    @DanelSwitalski ปีที่แล้ว

    witam,
    świetny materiał, rozumiem że z ospf też będzie działać?
    pozdrawiam
    Daniel

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว +1

      Tak, to będzie działać również z OSPF, przepraszam, jeśli tłumaczenie jest błędne przy użyciu tłumacza google

    • @DanelSwitalski
      @DanelSwitalski ปีที่แล้ว

      @@TheNetworkBerg witam, tłumaczenie ok; dziękuję za odpowiedz; czy ten rodzaj tunelu jest bardziej wydajny niż ip-ip lub inne?
      uprzejmie proszę o odpowiedz
      pozdrawiam
      Daniel

  • @christp42
    @christp42 ปีที่แล้ว

    Hey NetworkBerg! One more great video! Thank you.
    I have a question regarding the site-to-site connections setup.
    So you used different ports and two separate IP addresses on the Wireguard interface on Site-C to connect from there as the initiator of the VPN tunnels to the other two sites.
    What if you did this the other way around; that is: 1) you kept the port number common across all sites; 2) you had only one Wireguard interface with only one IP address on all sites; including Site-C and 3) connect from Site-A and Site-B as the initiators of the VPN communication to the same Wireguard interface (same public key; same port) on Site-C (using of course for all sites Wireguard IP addresses a /29 subnet or any other mask that would permit at least three IP addresses on the same network). Would that work?

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว

      Hello, Cite-C is not the initiator both Site-A and Site-B are initiators as only they have an endpoint and endpoint port set. You can setup dynamic routing using a single interface at Site-C (Meaning a single port across the board) but this needs a lot of tuning especially if you want to introduce OSPF.
      You will also in this case have to manually tweak every peer every time you want to advertise a new network as you will have to specify allowed-from addresses as Site-C (The Hub) cannot have 0.0.0.0/0 as an allowed-address to both Site-A and Site-B over its peers. You will experience routing loops if you do create the allowed-from addresses correctly and your routers will start to fall over.

  • @nikolashuminosky6987
    @nikolashuminosky6987 ปีที่แล้ว

    @The Network Berg - i don't understand why we need to ticke bgp on output-redistribute since we got RR running. I don't this that is the same case on v6

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว

      Hmmmmm I agree that this should just push through with using an RR, but for this WG setup I had to redist routes. Let me tweak around a bit and see if there is any answer. Will see if I can export the lab for more people to play around with the setup. I initially just used EBGP with default originates which worked awesomely but wanted to try and incorporate with IBGP as well

  • @safayethussain910
    @safayethussain910 ปีที่แล้ว

    Please enable OS7 prefix count option as soon as possible

  • @bachaparty402
    @bachaparty402 8 หลายเดือนก่อน

    Whhich vpn cheapest then mulvad as wireguard that support mikrotik

  • @darryndw
    @darryndw 5 หลายเดือนก่อน

    Things have changed allot in wiregaurd setups in ver 7.13.1 we need an updated video

  • @bachaparty402
    @bachaparty402 11 หลายเดือนก่อน

    Dear which is that cheapest wireguard service provider monthly

  • @bachaparty402
    @bachaparty402 8 หลายเดือนก่อน

    Is that method on mulvad

  • @bachaparty402
    @bachaparty402 8 หลายเดือนก่อน

    Bro my wireguard show tx error I am using mulvad I need your help

  • @mikkio5371
    @mikkio5371 ปีที่แล้ว

    Can one alos run ospf via wireguard

    • @TheNetworkBerg
      @TheNetworkBerg  ปีที่แล้ว

      Yes, if you use a single interface you will have to define static neighbors and using ptp type, else you can follow the exact same steps in this video, I could make another video featuring OSPF if that would make things easier?

    • @mikkio5371
      @mikkio5371 ปีที่แล้ว

      @@TheNetworkBerg thanks alot 🙏🙏 for the response . Would give it a try

    • @JimmieB
      @JimmieB 9 หลายเดือนก่อน

      Yes please run an OSPF over Wireguard vid. I can't get it to work. Added static neighbours with the WG interface and a PTP template but stuck in INIT on one end and nothing at the other end. Probably missing something. Great videos.@@TheNetworkBerg

    • @JimmieB
      @JimmieB 9 หลายเดือนก่อน

      doh! Matter fixed it. Was firewall issue. Allowed ospf (89) input and bingo all good.

  • @yith_telecom
    @yith_telecom 4 หลายเดือนก่อน

    I want to redirect all the remote sites traffic to a firewall below the main router. What should I configure in the main router?