pjhtech Tools
MikroTik

MikroTik WireGuard Stops After a Mobile IP Change

Compare endpoint-address and current-endpoint-address, NAT keepalive and responder roles after an LTE/5G or roaming endpoint changes.

If both WireGuard peers have responder=yes, neither initiates after the mobile address changes. Set the mobile side to responder=no with the stable peer’s reachable endpoint. If the failure happens only after an idle period, enable keepalive on the NATed side instead.

Both peers are responders: make the mobile side initiate

The NATed mobile side must initiate toward the stable endpoint. Setting responder=yes on both ends prevents that recovery path. If both are responders, set the mobile router’s existing peer to initiate. For this example the stable public endpoint is 203.0.113.40:51820; replace it with the real endpoint and peer name:

On the mobile router • existing peer, RouterOS 7.17+
/interface/wireguard/peers/set [find where name="example-stable-peer"] responder=no endpoint-address=203.0.113.40 endpoint-port=51820

The stable router’s peer for the mobile device can use responder=yes to stop initiating toward the old endpoint:

On the stable router • existing peer, RouterOS 7.17+
/interface/wireguard/peers/set [find where name="example-mobile-peer"] responder=yes

To see whether the mobile router actually sends UDP, run /ip/route/print detail and check an active underlay route covering the stable address, then /tool/sniffer/quick interface=lte1 ip-protocol=udp port=51820 while generating tunnel traffic. Replace lte1 and the port with the real underlay and endpoint port. Stop with Ctrl+C. Run /tool/sniffer/print first; retain any current capture and clear only stale filters before this test, using the explicit sniffer-filter procedure if needed.

On the stable end, /ip/firewall/filter/print stats where chain=input identifies a matching UDP permit or drop.

If a rule still restricts the old mobile source address, locate it with /ip/firewall/filter/print detail where chain=input. For a known new permitted source range, use /ip/firewall/filter/set <WireGuard-UDP-permit-id> src-address=<approved-mobile-prefix>, preserving its UDP/port/interface restrictions.

A freely roaming source requires a deliberate input-policy choice; do not simply remove restrictions from unrelated input rules.

Scope: RouterOS WireGuard; a mobile/NATed initiator connects to a stable reachable peer.

Read configured and learned state

Read-only • responder behavior here follows RouterOS 7.17+
/interface/wireguard/peers/print proplist=name,interface,endpoint-address,endpoint-port,current-endpoint-address,current-endpoint-port,persistent-keepalive,responder,last-handshake,rx,tx

endpoint-address is the configured destination. current-endpoint-address and port describe the source of the last correctly authenticated packet. The learned value is read-only and can change when NAT remaps the connection. Compare both address and port before/after the transition.

Use keepalive for an idle NAT mapping

When the NATed side needs to remain reachable while idle, persistent keepalive maintains authenticated traffic. Example for one existing peer on the initiator:

Configuration change • replace the unique peer name
/interface/wireguard/peers/set [find where name="example-stable-peer"] persistent-keepalive=25s

Keepalive does not remove CGNAT or supply a reachable rendezvous when neither side accepts incoming traffic. Save the previous interval and restore it if undoing the change.

Retest transition and idle recovery separately

After the address change, confirm current-endpoint-address and last-handshake update, then retry LAN traffic. If the handshake returns but LAN access does not, use the WireGuard LAN-access fixes.

References