Setting up Wireguard VPN behind a router

I have a Dream Machine Pro, and I’m trying to get Wireguard VPN working. Teleport works fine by the way.
However, when I use the Wireguard client from a remote computer, it appears to connect, but I get no internet or network access at all while the Wireguard connection is Active.

The problem is, it’s behind a standard Verizon router (model: Fios-G1100). I can remove the Verizon router, but I’m trying to get it to work without removing it for other reasons.

The IP address assigned to the DM from the Verizon router is 192.168.0.152

From the Verizon router, I’ve tried port forwarding port 51820 to 192.168.0.152. Tried it with UDP only as well as both TCP and UDP.
I tried setting the DMZ to the same IP number (is says it’s redundant if port forwarding is enabled for that IP).

There is a Static NAT section to add a NAT/NAPT Rule, but I did not give that a try yet because I wasn’t too sure how to configure that.

I also disabled UPnP on the Verizon router and made sure it wasn’t enable on the DM.
The router does say it’s in “bridge” mode, but I don’t think that’s true since it’s handing out IPs using DHCP.

I read that there is a possibility that Verizon could be blocking the port, and I may need to contact them. Not sure if anyone has had experience with that happening.

Any other suggestions on what to try? Does anything need to be configured on the DM that I am missing?

Hello! Thanks for posting on r/Ubiquiti!

This subreddit is here to provide unofficial technical support to people who use or want to dive into the world of Ubiquiti products. If you haven’t already been descriptive in your post, please take the time to edit it and add as many useful details as you can.

Please read and understand the rules in the sidebar, as posts and comments that violate them will be removed. Please put all off topic posts in the weekly off topic thread that is stickied to the top of the subreddit.

If you see people spreading misinformation, trying to mislead others, or other inappropriate behavior, please report it!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

Is it possible for your provider to set your Verizon router to bridge mode so your Dream Machine Pro can manage the network?

Did you mess with DNS settings for the wireguard setup?

Try manually changing it to 1.1.1.1 (or another public DNS) and see.

If the DNS is currently set to the router’s gateway (192.168.0.1 by default, I believe, but obviously you can change it) that might be causing some weird issues.

I also have Verizon though and have never used their router. They gave it to me with the plan and I was like “oh… thanks?” and it’s been in the box in the basement ever since. I think the only service it could provide for me would be showing me data usage on the FiOS website, but I can see that using my UDMP, so, :person_shrugging:

Why not set your UDM Pro as the primary and plug your G1100’s WAN into one of its LAN ports. You can then still use MoCA for your TV STBs if you are keeping the G1100 for that purpose.

I believe I tried that already setting it to 8.8.8.8 or something like that.

I think the port is possibly just being blocked somehow by Verizon. If not from their router, then from their office.

Still tinkering, but I may just do what Smorgas47 suggested, or remove their router altogether.

Thanks.

I didn’t think that would work, but might give that a try. Thanks for the suggestion.
I assume I would just need to manually enter in the IP address, Subnet mask, Gateway and DNS’s that come from Verizon into the UDM Pro.

Thanks.

Verizon’s public IP is provided via DHCP unless you have a fixed one.