Goal: have a router running a trusted operating system (OpenWRT), and routing all the LAN trafic to a Wireguard VPN.
In this howto we’ll use a Tetaneutral.net endpoint, but same applies to any Wireguard VPN provider.
Note on IPv6: Mullvad doesn’t provide an IPv6 subnet, so proper IPv6 support is not possible with Mullvad. Tetaneutral provides a /56 subnet, so we use SLAAC to give lan connected machines real IPv6.
Sources:
- https://mullvad.net/en/help/running-wireguard-router/
- https://www.azirevpn.com/support/guides/router/openwrt/wireguard
- https://wiki.tetaneutral.net/public/vpn_client_openwrt
Help:
- https://github.com/nitred/nr-wg-mtu-finder
- https://gist.github.com/nitred/f16850ca48c48c79bf422e90ee5b9d95
Prerequisites
- Up-to-date OpenWRT (Wireguard might not be available in old OpenWRT versions) with a working network setup. This was tested on OpenWRT 24.10
- A Wireguard peer config (ie. from Mullvad or any other provider)
Install Wireguard on OpenWRT
- Menu “System” → “Software”
- “Update lists”
- Click “Dismiss” when it’s finished
- Search “wireguard” in the “Filter” field
- Install “luci-proto-wireguard”
- “Update lists”
- Reboot OpenWRT
Configure OpenWRT
Configure Wireguard
- Menu “Network” → “Interfaces”
- Click on Add new interface…
- In the Name of the new interface field, enter « wg0 »
- In the Protocol of the new interface list, select WireGuard VPN
- Click “Create Interface”
- Click “Generate a new key pair”
- Give the public key to the VPN provider
- In “IP Addresses”:
- Add the IPv4 the client is assigned (sent by the wireguard provider).
- If using a provider that does give a proper IPv6 subnet (such as a /64 or /56), do not enter an IPv6 here as we will use SLAAC to give clients a real IPv6. Using IPv6 NAT is not covered by this howto.
- In the “Peers” tab, click “Add Peer”
- Paste the public key of the wireguard server
- In “Allowed IPs”, add “0.0.0.0/0” and “::/0” (that means all traffic will be allowed through the wireguard tunnel
- Check “Route allowed IPs”
- “Endpoint Host”: here goes our wireguard server IP address. Can be either IPv4 or IPv6 (both should work for IPv4 and IPv4 whatsoever)
- “Endpoint Port”: the port provided by our wireguard provider
- “Persistent Keep Alive”: if the OpenWRT router is behind a NAT (ie any kind of “internet box” in .fr at least), enter “20”. This can be changed if the connection hangs too often for example.
- Click “Save” to close the “Add Peer” window
- Click “Save” to close the “Add interface” window
- If the provider gives an IPv6 subnet, such as a /64 or /56 and you want
clients to have a proper IPv6:
- Edit “lan” interface
- Tab “Advanced Settings”
- “IPv6 assignment length” → disabled
- Tab “General Settings”
- “IPv6 address” → Enter the IPv6 given by the provider, use the :1 and subnet /64 (do not use /56)
- Tab “Advanced Settings”
- Edit “lan” interface
- Click on Add new interface…
Configure the firewall
- Menu “Network” → “Firewall”
- In “Zones”, click “Add”
- Name: wgzone
- Input: reject
- Output: accept
- Intra zone forward: reject
- Check the Masquerading box
- Check the MSS clamping box
- Covered Networks: check wg0, uncheck everything else
- Click “Save”
- In “Zones”, on the “lan ⇒ wan” zone, click “Edit”
- Check the MSS clamping box (sure about that?)
- Allow forward to destination zones: check wgzone, uncheck everything else
- Click “Save”
- Click “Save” again
Configure DNS servers (to make sure the internet box doesn’t have the list of visited domains)
You may either use Mullvad DNS servers or anything else you like. Lets see how.
Use Mullvad DNS
- Menu “Network” → “DHCP and DNS”
- Tab “Forwards”
- In the “DNS Forwards” field, add
10.64.0.1
- In the “DNS Forwards” field, add
- Tab “Forwards”
- Menu “Network” → “Interfaces” (this is optional but sometimes prevent leaks)
- Edit the “WAN” interface:
- In “Advanced settings” tab, uncheck “Use DNS servers advertised by peer”
- Edit the “WAN6” interface:
- In “Advanced settings” tab, uncheck “Use DNS servers advertised by peer”
- Edit the “WAN” interface:
Choose your DNS servers
- Menu “Network” → “Interfaces”
- Edit the “WAN” interface:
- In “Advanced settings” tab:
- Uncheck “Use DNS servers advertised by peer”
- Add trusted DNS servers in “Use custom DNS servers”, such as the Tetaneutral ones: 91.224.148.10 and 91.224.149.254
- Click “Save”
- In “Advanced settings” tab:
- Edit the “WAN6” interface:
- In “Advanced settings” tab:
- Uncheck “Use DNS servers advertised by peer”
- Add trusted DNS servers, such as the tetaneutral ones: 2a03:7220:8081:fd00::1 and 2a03:7220:8083:f800::1
- Click “Save”
- In “Advanced settings” tab:
- Click “Save” again
Time synchronization
Wireguard needs a correctly set clock to function properly. After an electricity outage or the router having been unplugged, wireguard won’t connect until the router’s clock is set. We can do it manually after such an event, or let it do it automatically regularly.
Synchronize time manually
- Menu “System” → “System”
- Sync time: click “Sync with browser”
Automatic time sync, aka NTP
You have to use an NTP server you know works. Unfortunately there is a big turnover so it might not last long. The IP in this example is not an NTP server anymore, for instance.
Wireguard needs a working clock to function properly. If the clock is not on time then Wireguard will not work, for example after an electricity cut. Let’s configure it.
- Menu Network → Routing
- Static IPv4 Routes
- Add
- Interface: wan
- Route type: unicast
- Target: 194.177.34.116/32 (chosen NTP server)
- Gateway: 192.168.1.1 (use your WAN gateway or leave it blank so it will use the default one)
- Save
- Network → Firewall
- Traffic Rules
- Add
- Name: NTP
- Protocol: UDP only
- Source zone: Device (output)
- Output zone: wan
- Destination address: in the “Custom” field, enter: 194.177.34.116/32
- Destination port: 123
- Action: accept
- Save
- System → System
- Time Synchronisation
- Uncheck “Use DHCP advertised NTP servers”
- Remove all NTP server candidates
- Add 194.177.34.116
- Click “Save and apply”
Save & reboot
- Menu “System” → “Reboot”
- Click “Perform reboot”
- Wait until you can reconnect to the Luci web interface, and connect
- Check your public IP address (ie on https://ip.me or https://mullvad.net)
- Check whether you have DNS leaks (ie on https://mullvad.net or https://www.dnsleaktest.com/)
Disable Wireguard
If for some reason you need to disable wireguard temporarily, do these steps. To re-enable it afterwards, just revert these.
- Edit lan→wgzone firewall zone, in Allow forward to destination zones: uncheck “wgzone” and check “wan”
- Edit wg interface, edit peer, uncheck “route allowed IPs”
- save & apply
- reboot