The ER-4 has been great with the Cavium hardware. No hardware offload issues like this.
Edit: The ER-X tops out around 500 Mbit with hardware offload turned off.
I get about 900 megabit on my gigabit fiber.
https://help.ubnt.com/hc/en-us/articles/115006567467-EdgeRou...
but i’d assume it should handle fast rates like this if hw offloading was on.
Then the pole outside my house got hit by lightning and fried the thing, and I replaced it with something from mikrotik.
The following article has an example of using policy based routing. Your setup isn't all that different, you don't need to have more than one default route in each routing table is all and you also might only need one additional route table.
https://help.ubnt.com/hc/en-us/articles/204952274-EdgeMAX-Po...
set protocols static table <table-number> interface-route 0.0.0.0/0 next-hop-interface wg1I migrated from Wireguard to ipsec quite a long time ago because it was less complicated for my particular needs. It has probably been close to 2 years. No one else seems to have taken up resolving the lingering problems with the configuration issues.
I'll give it another shot at some point, but it was more just to try out. I've also got ipsec set up on that router and that continues to work just fine.
If you do attempt it again there are "generate" commands which will generate they keys needed and place them in the proper area in the file system. Most of the guides to configuring Wireguard on edgeos seem unaware these exist and have people using the "wg" command directly instead to generate keys.
I think part of my issue is just that I need to do some more reading around what IPs should be what. It's usually clear what's going on in WireGuard-land, but not clear how that interacts with the other interfaces or the networks on either side.