Configure Teltonika as WireGuard Client

How do I import a WireGuard configuration file ?

I’d like the Teltonika router to connect to my WireGuard server running on my Firewalla at home.

I’ve got the file - but nowhere to upload.

Running 07.07.03 on a RutX

I am not aware of any facility to upload the tunnel settings to a RUTX, so assuming you are trying to create a Site-2-Site tunnel, you’ll need to enter the settings into the GUI at SERVICES > VPN > WIREGUARD or use the CLI.

You should know the settings from your home firewall to configure the tunnel on the Teltonika device or if not, then if the upload file is readable, you can take the values from that.

If you are new to Wireguard, then be aware that you’ll also have to tell your Home Firewall what the settings are for the Teltonika Peer.

Hmm… Simply have no idea how to get there.
Eg my home / the destination of the site2site seems to be not allowed by Teltonika software.

Is it just the GUI being restrictive?

Hi jkbkstr,

As I interpret the error message there are ipv4 and ipv6 addresses allowed,
and FQDNs (host/domain names) but no port numbers. Seems strange but
plausible.

Regards,
Timelapse Admin

I can see that at least TP-link supports it…
How to set up WireGuard VPN on TP-Link wireless router

Why is Teltonika not supporting the same ?

Best not compare tp-link because even within various platforms of tp-link their support of a Wireguard implementation varies A LOT.

It sounds like you are new to Wireguard, so look at the resources on the Teltonika site, figure out what you don’t understand and want to ask, then ask … we’ve all started off knowing nothing.

I can assure you, from my current implementations, that a Teltonika RUTX is capable of establishing a Site-2-Site connection with a tp-link peer and many others, as a Site-2-Site tunnel.

You don’t explain what you are trying to achieve. Maybe if you describe your ‘end goal’ then that will put your question into context.

New to WireGuard yes - and unable to find any ressources on Teltonika forum showing me how I can connect to Endpoint=XXXXXXXXXXX.d.firewalla.org:5XXXX …
Router does not seem to allow an endpoint on a separate port.

Hi jkbstr,
not in the forum but in the wiki. A quick search reveals:
Wireguard Peer To Peer Configuration example
and
WireGuard Configuration Example

In the tab “Advanced settings” you can select the port number.

Regards,
Timelapse Admin

Yes it does! You need to read up on Wireguard in general to understand its basic implementation ‘needs’ … you need to understand how and why it works.

An example of an actual Peer config that I use for Site-2-Site …

With regards to the ‘Allowed IPs’ this is what I use for Site-2-Site for my particular Use Case but you need to assess if they’re fit for your purpose. It will allow any IP from the ‘other side’ of the tunnel access to the network ‘this side (RUTX)’ - IPv4 & IPv6. There are some particular nuances with the addresses but are probably not a conversation on this thread.

Also be aware (as you mention tp-link), that if you decide to mimic bits of the above configuration as the Peer settings on your other firewall/router and it is a tp-link … SOME of their device implementations wont allow you to enter the Allowed IP’s above e.g. won’t allow 0.0.0.0/1 but will allow 0.0.0.0/0. In addition, some of their ‘flavours’ won’t allow an FQDN/DDNS as an Endpoint Host but require an IP address.

This topic was automatically closed after 15 days. New replies are no longer allowed.