

So I don't think that your internet connection working via Surfshark. You should note that user will NOT be able to visit other subnets UNLESS you add additional rules allowing this PRIOR to the subnet being forced out the internet via wireguard.Īdd dst-address=subnetA action=lookup-only-in-table table=main In addition another consideration is subnet to subnet traffic. You could have users select this on a WIFI basis, with SSIDs identifying the vlan/subnet and thus users decide. Which Subnet going out which wireguard tunnel. add dst=address=0.0.0.0/0 gwy=Wireguard-Denmark table=use-WG-DenmarkĪdd dst=address=0.0.0.0/0 gwy=Wireguard-Finland table=use-WG-FinlandĪdd dst=address=0.0.0.0/0 gwy=Wireguard-USA table=use-WG-USAĪdd dst=address=0.0.0.0/0 gwy=Wireguard-Germany table=use-WG-GermanyĪdd src-address=subnetA action=lookup table=use-WG-DenmarkĪdd src-address=subnetB action=lookup table=use-WG-FinlandĪdd src-address=subnetC action=lookup table=use-WG-USAĪdd src-address=subnetD action=lookup table=use-WG-GermanyĪs stated need more info for routing rules. as many tables needed, one for each wg configurationī. This will activate smart DNS for your new IP address. Once logged in to your account on, go to the smart DNS page. If you are planning on buying enough vpns from a provider, thenĪ. Make sure that your laptop or phone is connected to the same network as the device on which you will use smart DNS. Set allow-remote-requests=yes servers=162.252.172.57,149.154.159.92,8.8.8.8Īdd address=192.168.1.0/24 list=SurfsharkĪdd action=accept chain=input disabled=yesĪdd action=masquerade chain=srcnat log=yes out-interface=ether1.ISPĪdd action=masquerade chain=srcnat out-interface=Wireguard-DenmarkĪdd disabled=no distance=1 dst-address=0.0.0.0/0 gateway=Wireguard-Denmark \ Set disable-ipv6=yes max-neighbor-entries=8192Īdd allowed-address=0.0.0.0/0 endpoint-address=195.26.6.39 endpoint-port=\ĥ1820 interface=Wireguard-Denmark public-key=\ Set supplicant-identity=MikroTikĪdd name=pool1.LAN ranges=192.168.50.2-192.168.50.100Īdd address-pool=pool1.LAN interface=BridgeLAN name=server1.LAN Set name=ether1.ISPĪdd listen-port=13231 mtu=1420 name=Wireguard-Denmark
