• Wireguard site2site NAT / IP of tunnel shown instead of real IP

    2
    0 Votes
    2 Posts
    175 Views
    B

    To anyone having the same problem follow this guide
    https://blog.matrixpost.net/set-up-wireguard-site-to-site-vpn-on-pfsense/

    or in short, do not set an upstream gateway and set static routes as allowed ips.

  • 0 Votes
    1 Posts
    140 Views
    No one has replied
  • Wireguard Gateway not coming up after reboot.

    6
    0 Votes
    6 Posts
    990 Views
    Y

    @GTR_991 Hi guys,

    I have the same issue. I'm running pfsense CE 2.7.2 and after restart I have to enable the wireguard gateway, then start the wireguard service.
    I was thinking to do a script and add it to a cron job, but I couldn't find the right command that can enable the wireguard gateway. Any help is much appreciated. thanks.

  • Errors out in WG

    4
    0 Votes
    4 Posts
    674 Views
    W

    Same here. Does not seem to do any harm but it just feels not right, having so much errors on an interface and not knowing why...

  • PIA using pfSense WireGuard Package

    28
    0 Votes
    28 Posts
    5k Views
    B

    Thanks for the nice drawing. I will try again and see if it will work.

  • Routing traffic from specific subnet and port through Wireguard tunnel

    3
    0 Votes
    3 Posts
    384 Views
    J

    @The-Party-of-Hell-No

    Hi,

    Thanks for your reply. Yes I've set the tunnel up with all NAT rules in place, following guides, to the point of routing all traffic via the tunnel.

    Just wasn't sure of the next steps and if a firewall rule would work.

    I'll give that a go and see if it works as I'd like.

  • WireGuard and ProtonVPN

    7
    0 Votes
    7 Posts
    726 Views
    A

    @Bob-Dig said in WireGuard and ProtonVPN:

    Personally I wouldn't change my DNS-Servers to Proton but change the DNS-Server for some hosts only to always use external DNS, which will then go through the VPN for those hosts.

    Could you please, show example of firewall rule to pass DNS request via VPN fore some hosts?

  • Wireguard ICMP protocol

    1
    0 Votes
    1 Posts
    171 Views
    No one has replied
  • UDP Transport Issue

    1
    0 Votes
    1 Posts
    107 Views
    No one has replied
  • WireGuard Site-to-Site VPN and backup path for dual WAN

    1
    0 Votes
    1 Posts
    134 Views
    No one has replied
  • wireguard mtu issues

    7
    0 Votes
    7 Posts
    2k Views
    yon 0Y

    i have to setup mss to 1280.

  • Add WAN export interface for wiregaurd

    1
    0 Votes
    1 Posts
    109 Views
    No one has replied
  • Why is wiregaurd not pushing updates?

    1
    0 Votes
    1 Posts
    132 Views
    No one has replied
  • Wireguard client routing specific subnet

    1
    0 Votes
    1 Posts
    97 Views
    No one has replied
  • Download configuration button provides incomplete configuration file

    1
    0 Votes
    1 Posts
    105 Views
    No one has replied
  • surfshark guide for pfsense wireguard

    32
    0 Votes
    32 Posts
    6k Views
    T

    @The-Party-of-Hell-No

    Conversation I had with technician at Surf Shark about two WireGuard tunnels simultaneously:

    another question can I use the same tunnel and have multiple gateways(Peers) going to different surfshark servers through the same tunnel?
    Saul Buchanan
    's avatar
    Not at the same time, but you can use the same tunnel with different peers, yes.
    Okay, can I create individual tunnels for each peer (Surfshark server) I wish to use as a gateways.
    I have done this using the openvpn protocol
    Saul Buchanan
    's avatar
    Essentially yes.
    Isn't the problem generating keys for each tunnel?
    Saul Buchanan
    's avatar
    Not really, as you can use the same private keys with multiple tunnels. I would just like to emphasize that multiple connections at a time from the same device will most likely encounter issues.

    Untitled.jpg

    The challenge I ran into was thinking the endpoint port (51820) had to match the tunnel port.. It cannot be changed - obviously it is set by SurfShark, but it means both tunnels share the same endpoint port.

    It seems to work:

    Untitled2.jpg

  • public key must be specified

    1
    0 Votes
    1 Posts
    141 Views
    No one has replied
  • Wireguard not running despite following multiple guides

    2
    0 Votes
    2 Posts
    256 Views
    J

    @Frosch1482 For starters change the interface to a /24. You have it as a /32.

  • Wireguard no handshake

    1
    0 Votes
    1 Posts
    210 Views
    No one has replied
  • No handshake via Mullvad

    3
    0 Votes
    3 Posts
    263 Views
    T

    @TeeNetGate1 Adding in more testing, from pfsense I can ping the endpoint IPv4 & v6. But still not handshake.

    I took a server I know works, from the 3100, but it does not work.

    I have added in an interface IP, which i can ping and this does not work.

    Do I have a lemon of a pfsense box?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.