Skip to content

VPN Setup

VPN Type: WireGuard
Name: vpn-srv-zrh-01
Server Address: 192.168.1.100 (WAN1)
Port: 51820
Alternate Address: vpn.microsoftlab.ch (for clients)
Gateway/Subnet: 10.60.60.1/24
Usable IPs: 253
IP Range: 10.60.60.2 - 10.60.60.254
DNS Server 1: 10.30.30.15
DNS Server 2: 10.30.30.10
NameInterface IP
HP Elitebook10.60.60.2
[Interface]
PrivateKey = <client-private-key>
Address = 10.60.60.2/32
DNS = 10.30.30.15, 10.30.30.10
MTU = 1280
[Peer]
PublicKey = ruj9vpJW/PaYvkBLdztqBdcoh0VQpBy+m5Qduxmxv1k=
AllowedIPs = 10.1.1.1/24, 10.10.10.0/24, 10.30.30.0/24, 10.40.40.0/22, 10.50.50.0/24, 10.60.60.1/32
Endpoint = vpn.microsoftlab.ch:51820
NetworkPurpose
10.1.1.1/24Default VLAN (UniFi devices)
10.10.10.0/24Management VLAN
10.30.30.0/24Server VLAN
10.40.40.0/22Client VLAN
10.50.50.0/24DMZ VLAN
10.60.60.1/32VPN Gateway only

Note: Split tunnel configuration - only internal traffic goes through VPN.

Required for external VPN access:

External Port: 51820
Protocol: UDP
Internal IP: 192.168.1.100 (UniFi Gateway WAN)
Internal Port: 51820

When connecting from inside the network using the external DNS name (vpn.microsoftlab.ch), NAT loopback may not work on all ISP routers.

Use internal DNS or IP when inside the network, external DNS when outside.