Zero-route BOVPNVif and Guest-Wifi possible?

I try to configure a T125W with a zero-route BOVPNVif and guest-wifi. BOVPNVif works and everything is connected with the HQ but when I connect a client with the guest-wifi, it is not possible to open a website. All traffic will be routed to BovpnVif. Also when I activate SD-WAN. When I put Any in the To-Field, I am able to open websites. When I disable BovpnVif, I am also able to open websites. I also created a second SD-WAN with BovpnVif and selected this SD-WAN in the BovpnVif (in and out) rules.

2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39808 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 2847447664 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic
2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39818 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 101959561 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic
2026-08-24 13:05:06 Deny 192.168.216.204 54.212.248.139 https/tcp 39834 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3135006364 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic

HTTPS/HTTP Rule for guest-wifi (placed on order 1+2):

HTTPS/HTTP
From: WLAN—AP2
To: WAN (External-Interface, I also tried Any-External)
SD-WAN Action: WAN
1 to 1 NAT and Dynamic NAT enabled.

BovpnVif

Address Family: IPv4
VPN Routes → Route To: 0.0.0.0/0 Metric/Distance: 1
Virtual IP addresse:
  Local: 10.255.255.2
  Peer: 10.255.255.1
When I set the Metric to 100, it is the other way around. Everything will be routed to WAN.

BovpnVif.out Rule for LAN (placed on order 8+9):

Any
From: LAN
To: BovpnVif

FirewareOS: 2026.2.1.B740867

Am I doing something wrong or what configuration is best practice?

Answers

  • Have you tried not selecting a SD-WAN action on your HTTPS & HTTP policies?

  • Yes, but unfortunately the same problem.

    2026-08-24 15:06:24 Deny 192.168.216.204 104.17.71.206 https/tcp 39164 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 1061649089 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic
    2026-08-24 15:06:24 Deny 192.168.216.204 104.18.90.22 https/tcp 48864 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3064458878 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic
    2026-08-24 15:06:24 Deny 192.168.216.204 104.18.90.22 https/tcp 48876 443 WLAN-AP2 BovpnVif Denied 60 63 (Unhandled Internal Packet-00)  proc_id="firewall" rc="101" msg_id="3000-0148" fqdn_dst_match="watchguard.com" tcp_info="offset 10 S 3200476205 win 61690" flags="SR" duration="0 seconds" sent_pkts="1" rcvd_pkts="0" sent_bytes="60" rcvd_bytes="0" 	Traffic
    
  • Bruce_Briggs
    edited August 24

    Seems like it should work.

    Best to open a support case to get a WG rep to review your config and help resolve it.

    Should you find a resolution, please post it for others to find.