
Completed
Posted
Paid on delivery
I need a full working Layer-2 bridge over WireGuard on a Mikrotik RB5009. The goal is to carry an entire VLAN through the tunnel (EoIP-style) so that devices on the remote end appear inside my existing Korean network, each with a 1:1 public-to-private NAT. Within this single router I also want the following tuned or enforced: optimal MTU and MSS clamping, strict port isolation and Bridge-Horizon separation inside the bridged VLAN, DNS redirection that eliminates any chance of DNS leak, a mangle rule that locks every packet to TTL-128, and a hard kill-switch that drops all traffic the moment the WireGuard peer is unreachable. Anti-detection techniques suitable for a GPN scenario must be part of the design. I am comfortable applying an .rsc file myself, but I need you to supply a complete, tested configuration along with a short explanation of each key rule so I can maintain it later. Deliverables • Ready-to-import Mikrotik .rsc or CLI script covering WireGuard, bridge, NAT, firewall/mangle, and kill-switch • Peer-side settings (server or VPS) required to establish the tunnel • One-page reference explaining the purpose of every custom rule and the MTU/MSS logic I will test with real traffic; payment will be released once VLAN bridging, 1:1 NAT, DNS leak-proofing, and the kill-switch all pass.
Project ID: 40405941
7 proposals
Remote project
Active 19 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

With over a decade's worth of experience as a Network, Cybersecurity, VoIP, and System Engineer, I believe my skill set perfectly aligns with your Mikrotik WireGuard L2 Bridge project. Furthermore, my skills extend beyond just network administration to include critical areas like VPNs and security, which are precisely what your project necessitates. I have specialized in fortifying infrastructures against sophisticated threats. This becomes especially relevant considering you require robust anti-detection techniques suitable for a GPN scenario. My background in platforms such as Cisco ASA, Fortinet or Palo Alto would be beneficial here. In delivering the project, I value clear documentation as much as you do. My approach involves providing not only the ready-to-import Mikrotik .rsc or CLI script but also a one-page reference document explaining not only the purpose of every custom rule but also the underlying logic behind MTU/MSS decisions. Beyond just completing your task efficiently, my goal is to equip you with the knowledge that enables maintaining the system yourself. So let's join hands! With my extensive proficiency and passion for delivering quality work worthy of best practices, I can ensure your project meets all your expectations - from VLAN bridging to 1:1 NAT and everything in between.
$180 USD in 2 days
7.2
7.2
7 freelancers are bidding on average $136 USD for this job

Hi there, I will deliver a production-ready WireGuard L2 bridge on your MikroTik RB5009 that carries a full VLAN across the tunnel with 1:1 public-to-private NAT, MTU/MSS tuning, Bridge-Horizon separation and strict port isolation; I’ve built similar MikroTik RBxx WireGuard-to-VPS bridges and NAT mappings for single-router Korean network topologies. - Ready-to-import .rsc / CLI: WireGuard peer, bridge + VLAN passthrough, 1:1 NAT rules, MTU/MSS clamping and anti-detection tweaks - Peer-side config: exact server (VPS) WireGuard keys, IPs, routing, and firewall snippets to accept the L2 peer - One-page reference: explanation of each firewall/mangle rule, MTU/MSS math, and kill-switch behavior - Risk/quality-control: staged deployment with backup checkpoint and rollback plan (production-safe rollout) Skills: ✅ WireGuard ✅ MikroTik RouterOS (RB5009) ✅ VLAN/bridge bridging and 1:1 NAT ✅ Firewall/mangle, MTU/MSS tuning ✅ DNS redirection and leak prevention Certificates: ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m available to start immediately. Is this already running on a live production server (RB5009) or should I provide a staged/test config first? Best regards,
$120 USD in 1 day
6.4
6.4

With over a decade of experience in network administration and security, my team and I are well-positioned to tackle your Mikrotik WireGuard project. Our core expertise lies in building and maintaining robust, secure infrastructures while optimizing for performance and reliability - skills that align perfectly with your requirements. Additionally, our deep knowledge of DevOps practices ensures we can provide efficient solutions that reflect innovation and long-term value for your business. Specifically, our proficiency in network administration guarantees we can deliver on all aspects of your project description. From establishing a full working Layer-2 bridge over WireGuard to implementing optimal MTU and MSS clamping, strict port isolation, and bridge-horizon separation inside the bridged VLAN- we're well-prepared to handle it all. With each custom rule, we'll provide a short explanation, ensuring you have the necessary information to maintain the configuration. Moreover, our approach includes rigorous testing to ensure everything works as intended under real traffic conditions - this further strengthens our suitability for the task at hand. Rest assured, we won't consider the job complete unless VLAN bridging, 1:1 NAT, DNS leak-proofing, and the kill-switch all pass your testing. Let's connect so we can discuss your unique requirements!
$105 USD in 7 days
2.8
2.8

As an accomplished network and system administrator, I have over a decade of experience with tools like MikroTik Router, valuable in handling your current project. I have hands-on knowledge of configuring and managing various overlay network VPNs including WireGuard which aligns perfectly with your requirement. Furthermore, my competency in performing VLAN bridging, NAT, firewall/mangle configuration will be pivotal in providing you with a fully operative Layer-2 bridge over WireGuard within your Mbikrotik RB5009 system. I understand the unique demands of your project - strict port isolation, DNS leak-proofing, anti-detection techniques, and the hard kill-switch. By applying my skills as a Certified Ethical Hacker (CEH), along with my deep understanding of network security mechanisms, I will create a fortified environment that allows you to carry out secure and anonymous communications across distributed systems. Additionally, my comprehension of network optimisation; like tuning the optimal MTU and enforcing Microsoft Server to handle DNS queries can further enhance the overall efficiency of your system. Your satisfaction matters the most to me; payment will be processed only once the VLAN bridging, 1:1 NAT, DNS leak-proofing, and kill-switch are all verified using actual traffic tests. So let's seal the deal; I can't wait to get started on making your managed Korean network even more seamless!
$120 USD in 1 day
0.0
0.0

Boss, this is exactly the kind of MikroTik setup I enjoy building — but I’ll be straight with you: doing a true Layer-2 bridge over WireGuard with EoIP-like behavior + clean NAT + leak-proofing + anti-detection needs careful tuning, not just a quick script dump. I can deliver a fully tested .rsc with: WireGuard + L2 bridge (VLAN carried properly) 1:1 NAT per client inside the bridged network MTU + MSS optimized (no fragmentation issues) DNS fully forced (zero leaks) TTL locking + mangle tuning Proper kill-switch (hard drop if WG goes down) Clean bridge isolation using Horizon Peer-side (VPS) config included I’ll also include a clear 1-page explanation so you’re not stuck later. Price: $120 Time: 2 days (including testing logic and edge cases) Quick question before I start: Do you already have a VPS/location in Korea ready, or should I design the peer config assuming a fresh server (and which OS)?
$120 USD in 2 days
0.0
0.0

Gyeonggi-do, Korea, Republic of
Payment method verified
Member since Apr 29, 2026
₹750-1250 INR / hour
$250-750 USD
₹37500-75000 INR
₹1500-12500 INR
₹600-1500 INR
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
₹12500-37500 INR
$30-250 USD
$10-30 USD
$50-100 AUD
$25-50 USD / hour
₹75000-150000 INR
₹12500-37500 INR
$10-30 USD
$30-250 AUD
$25-50 USD / hour
$15-25 USD / hour
$250-750 USD