亲爱的用户,在Road Warrior模式下,按照@msatter和@sindy对WireGuard的建议使用NoTrack,读了几遍,做了多次测试,没有成功。
这是防火墙配置的相关部分:
/interface wireguard add listen-port=13231 name= wireguard private-key="…" disabled=no /interface wireguard peers add allow -address=10.10.10.2/32 end -port=13231 interface= wireguard public-key="…" disabled=no /ip address add address=10.10.10.1/30 interface= wireguard network=10.10.10.0 /ip firewall raw add action=notrack chain=prerouting interface= wireguard /ip firewall filter add action=accept chain=input connection-state=established,related,untracked /ip firewall filter addAction =accept chain=input dst-port=13231…/ip firewall filter add action=accept chain=forward connection-state=established,related,untracked /ip firewall filter add action=accept chain=forward connection-state=untracked interface=WireGuard out-interface-list=LAN /ip firewall filter add action=accept chain=forward connection-state=untracked interface=WireGuard out-interface=WAN
目标是检查绕过连接跟踪是否会节省一些CPU。
我可以通过隧道连接,但不能连接到互联网或局域网设备,我做错了什么?