How can I provide Layer 2 connectivity over WireGuard using VXLAN?
In category Routers .
WireGuard provides Layer 3 connectivity and does not transport Ethernet frames directly. VXLAN can extend a Layer 2 network over an existing WireGuard connection, allowing Ethernet traffic, including broadcasts, to pass between remote LANs.
VXLAN is available on supported Advantech routers starting with ICR-OS 6.6.1. Check availability for your particular router model before configuring the connection. VXLAN support and overview
Basic configuration
Establish WireGuard connectivity between the routers. When using a central WireGuard server, ensure that routing and firewall rules allow communication between the routers’ WireGuard addresses.
Open Configuration → VXLAN on each router.
Set Local Address to the router’s own WireGuard IP address and Remote Address to the other router’s WireGuard IP address.
Configure the same VNI and UDP port on both ends of the tunnel. The standard VXLAN port is 4789.
Enable Bridged mode for VXLAN and include the required LAN Ethernet interface in the same bridge.
Allow VXLAN traffic from the peer’s WireGuard address through the firewall. Select an MTU that accounts for both VXLAN and WireGuard overhead.
For the parameter descriptions, see the router configuration manual.
Verified test
Layer 2 connectivity was successfully tested with three client routers connected through a WebAccess/DMP (WADMP) WireGuard server.
One router provided a DHCP server on the extended LAN, while the other routers operated as DHCP clients. DHCP address assignment worked across the VXLAN connections. Additional devices connected to the client routers’ LAN interfaces also operated successfully.
This test verified Layer 2 connectivity between the LANs over the existing WireGuard infrastructure.
Connecting a Windows PC
In the tested arrangement, an additional router was placed in front of the PC. This router terminated both WireGuard and VXLAN, while the PC used a standard Ethernet connection to its LAN port.
No WireGuard or VXLAN software was required on the PC. A direct software-only Windows connection was not part of this test.
Deployment notes
The connected LANs form a shared Layer 2 segment. Ensure that IP addresses are unique and DHCP servers do not conflict. Avoid bridge loops when connecting multiple sites.
VXLAN does not provide encryption itself; its traffic should remain inside the WireGuard tunnel. Account for the combined encapsulation overhead when checking MTU and testing larger packets.
.png)
DHCP server:.png)
.png)