Mikrotik WireGuard L2 Bridge
Budget: $10 – $200 USD
I need a full working Layer-2 bridge over WireGuard on a Mikrotik RB5009. The goal is to carry an entire VLAN through the tunnel (EoIP-style) so that devices on the remote end appear inside my existing Korean network, each with a 1:1 public-to-private NAT.
Within this single router I also want the following tuned or enforced: optimal MTU and MSS clamping, strict port isolation and Bridge-Horizon separation inside the bridged VLAN, DNS redirection that eliminates any chance of DNS leak, a mangle rule that locks every packet to TTL-128, and a hard kill-switch that drops all traffic the moment the WireGuard peer is unreachable. Anti-detection techniques suitable for a GPN scenario must be part of the design.
I am comfortable applying an .rsc file myself, but I need you to supply a complete, tested configuration along with a short explanation of each key rule so I can maintain it later.
Deliverables
• Ready-to-import Mikrotik .rsc or CLI script covering WireGuard, bridge, NAT, firewall/mangle, and kill-switch
• Peer-side settings (server or VPS) required to establish the tunnel
• One-page reference explaining the purpose of every custom rule and the MTU/MSS logic
I will test with real traffic; payment will be released once VLAN bridging, 1:1 NAT, DNS leak-proofing, and the kill-switch all pass.
Within this single router I also want the following tuned or enforced: optimal MTU and MSS clamping, strict port isolation and Bridge-Horizon separation inside the bridged VLAN, DNS redirection that eliminates any chance of DNS leak, a mangle rule that locks every packet to TTL-128, and a hard kill-switch that drops all traffic the moment the WireGuard peer is unreachable. Anti-detection techniques suitable for a GPN scenario must be part of the design.
I am comfortable applying an .rsc file myself, but I need you to supply a complete, tested configuration along with a short explanation of each key rule so I can maintain it later.
Deliverables
• Ready-to-import Mikrotik .rsc or CLI script covering WireGuard, bridge, NAT, firewall/mangle, and kill-switch
• Peer-side settings (server or VPS) required to establish the tunnel
• One-page reference explaining the purpose of every custom rule and the MTU/MSS logic
I will test with real traffic; payment will be released once VLAN bridging, 1:1 NAT, DNS leak-proofing, and the kill-switch all pass.