68
W&T
WireGuard VPN server
7�5 Step by step: VPN access for a mobile device
There is a machine in the island network whose internal web
interface is to be accessed via the Internet from an Android
mobile device.
The example assumes that the Microwall is already set up as a
NAT router between the intranet at
Network1
(yellow) and the
network island at
Network 2
(green).
1� Preparations
Android WireGuard APP
- This must be installed on the And-
roid mobile device. To do this, enter „Wireguard“ in the Play-
store search.
Internet router/perimeter firewall
- A NAT rule is required in
the perimeter firewall (possibly a DSL router) responsible for
connecting the intranet to the Internet or other higher-level
network. This must forward incoming UDP packets from the
Internet side with the destination port 10001 to the intra-
net-side IP address of the Microwall VPN.
Dynamic IP addresses
- If the Internet connection of the intra-
net only has dynamic IP addresses of the provider on the WAN
side, the service of a DynDNS provider must be used. In this
case, the IP address must be replaced by the corresponding
host name as the end point in the VPN client configuration.
Island
10.10.0.0/16
Intranet
10.20.0.0/16
Microwall
VPN
Internet router/
Perimeter firewall
Internet
Island
maschine
Android
Mobile device
WireGuard VPN tunnel
10.10.0.10
10.20.0.10
VPN server:
10.3.3.1
VPN client:
10.3.3.5
92.200.200.100
Summary of Contents for 55211
Page 6: ...W T ...
Page 7: ...7 W T Subject to error and alteration 1 Legal information and safety ...
Page 12: ...12 W T ...
Page 56: ...56 W T Operation modes and rule configuration ...
Page 80: ...80 W T WireGuard VPN client ...
Page 84: ...84 W T WireGuard VPN Box to Box ...
Page 111: ...111 W T Subject to error and alteration Appendix Technical data and form factor ...