Zero-route BOVPNVif and Guest-Wifi possible?
I try to configure a T125W with a zero-route BOVPNVif and guest-wifi. BOVPNVif works and everything is connected with the HQ but when I connect a client with the guest-wifi, it is not possible to open a website. All traffic will be routed to BovpnVif. Also when I activate SD-WAN. When I put Any in the To-Field, I am able to open websites. When I disable BovpnVif, I am also able to open websites. I also created a second SD-WAN with BovpnVif and selected this SD-WAN in the BovpnVif (in and out) rules.
2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39808 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 2847447664 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic 2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39818 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 101959561 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic 2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39834 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3135006364 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic
HTTPS/HTTP Rule for guest-wifi (placed on order 1+2):
HTTPS/HTTP From: WLAN—AP2 To: WAN (External-Interface, I also tried Any-External) SD-WAN Action: WAN 1 to 1 NAT and Dynamic NAT enabled.
BovpnVif
Address Family: IPv4 VPN Routes → Route To: 0.0.0.0/0 Metric/Distance: 1 Virtual IP addresse: Local: 10.255.255.2 Peer: 10.255.255.1 When I set the Metric to 100, it is the other way around. Everything will be routed to WAN.
BovpnVif.out Rule for LAN (placed on order 8+9):
Any From: LAN To: BovpnVif
FirewareOS: 2026.2.1.B740867
Am I doing something wrong or what configuration is best practice?
Answers
-
Have you tried not selecting a SD-WAN action on your HTTPS & HTTP policies?
0 -
Yes, but unfortunately the same problem.
2026-08-24 15:06:24 Deny 192.168.216.204 104.17.71.206 https/tcp 39164 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 1061649089 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic 2026-08-24 15:06:24 Deny 192.168.216.204 104.18.90.22 https/tcp 48864 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3064458878 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic 2026-08-24 15:06:24 Deny 192.168.216.204 104.18.90.22 https/tcp 48876 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3200476205 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" Traffic
0 -
Seems like it should work.
Best to open a support case to get a WG rep to review your config and help resolve it.
Should you find a resolution, please post it for others to find.
0 -
I’d check the routing and SD-WAN policy interaction first, because it sounds like the guest network is unintentionally inheriting the zero-route BOVPNVif path. I would also verify the destination matching and rule order, especially since setting Any in the To field restores Internet access.
0
