

So, I don’t use OpenWRT (for main router), but generally in each vlan you will need:
- The WG interface in that vlan so all hosts can send their traffic to it.
- DHCP server that sends the WG (local side IP) as the default route. Can also set statically on all devices. When a device on that vlan wants to send a packet to the internet it will do an ARP request for the local vlan IP then forward the IP packet to the router.
- You will need to do some NAT as you have many private IPs for your devices in the vlan mapped to one IP given through WG. Packets that hit the WG interface should be forwarded down the tunnel with a translated source address of the local WG IP and whatever ports are in use publicly. Return packets reverse this operation.
- Repeat for additional vlans.












Bullet. Because the best dispenser on the market looks kind of like a bullet.