• Strange login from another country

    wireguard
    5
    1
    0 Votes
    5 Posts
    1k Views
    P
    @bob-dig said in Strange login from another country: @pastic said in Strange login from another country: I realise something as I write this: are there 'two levels' involved here? The wireguard rule will let everyone through the firewall on the specified port, but having passed the firewall block then the wireguard service will still refuse everyone that does not have the configured keys? Yes. Hard to believe that this is news to you, you are setting up a graylog server, which is advanced stuff in my book. Let's call it a blind spot. :-) I don't work with networks, it's just a hobby. And until this Wireguard 'project' I always had pfsense blocking everything from the outside. And yes, I did struggle a bit setting up graylog, but it was fun. Thanks!
  • Wireguard wont reconnect after losing gateway access till pfsense reboot

    3
    0 Votes
    3 Posts
    1k Views
    I
    I have two internet connections on my pfsense. I also noticed sometimes the VPN connection stays up but it stops routing data over the wireguard link till i restart the wireguard service.
  • The "(Copy)" seems not working

    1
    0 Votes
    1 Posts
    230 Views
    No one has replied
  • VPN problemas para ver clientes con dos tarjetas de red

    1
    0 Votes
    1 Posts
    295 Views
    No one has replied
  • wireguard server,how to change the MTU?

    6
    0 Votes
    6 Posts
    1k Views
    M
    @jarhead said in wireguard server,how to change the MTU?: @msibyte said in wireguard server,how to change the MTU?: @jarhead In which section to change this? [image: 1678788023297-wg.png] [image: 1679092999787-screenshot_20230318014317.png] enabling LAN - disables access to the website via an external IP
  • Configuration vpn wireguard

    wireguard
    1
    0 Votes
    1 Posts
    771 Views
    No one has replied
  • Wireguard gateway packet loss

    2
    1
    0 Votes
    2 Posts
    699 Views
    X
    hey guys, i guess it isn't a common problem. i think i fixed it by changing the MSS and MTU to 1420 on the Wireguard interface. hope this may help someone in the future.
  • Multi WAN with wireguard confused

    11
    0 Votes
    11 Posts
    3k Views
    4
    @bob-dig I will use wireguard as the primary with failover to openvpn and setup a setup openvpn to deal with the country exception. shame, seems wireguard does perform better on the same h/w are access
  • Wireguard configuration help for connecting from the "same network"

    2
    0 Votes
    2 Posts
    331 Views
    B
    Ok - disregard the above post. If I could delete it, I would. It it turns out what I am trying to achieve works flawlessly. I had another problem in my wg config (with the firewall rules) that was causing my icmp pings to not return, which I assumed was a wg issue.
  • Roadwarrior across Site to Site

    3
    0 Votes
    3 Posts
    536 Views
    X
    @jarhead that did it. added the RoadWarrior tunnel ip to the allowed ip on parents peers. thanks man, that was easy!!
  • Remove packages before update - WireGuard

    Moved
    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • Wireguard Site-to-Site Setup - Errors on Interface

    13
    0 Votes
    13 Posts
    5k Views
    T
    @keyser said in Wireguard Site-to-Site Setup - Errors on Interface: @tman222 Just out of curriosity: What boxes are on either end of that tunnel? I’m looking for what throughput can be expected for the SG-2100 ARM based boxes, but no-one seems to know :-) (With 900mbps+ I know you are not ) Hi @keyser - hardware on both sides fairly powerful (at least as far as firewalls concerned): System on one side is driven by a Xeon D-1518 CPU, System on the other side has a Intel Core i3 10100 CPU. Bear in mind that those results are from a single stream iperf3 test using default settings (i.e. large 1500 byte packets) and that the site to site latency is only a few milliseconds.
  • Slow ssh between LANs. Not sure what to do.

    1
    0 Votes
    1 Posts
    321 Views
    No one has replied
  • SG-2100 ARM64 Wireguard experience?

    1
    1 Votes
    1 Posts
    437 Views
    No one has replied
  • Wireguard Pfsense gets handshake with ports closed...

    4
    0 Votes
    4 Posts
    913 Views
    jimpJ
    The service has nothing to do with the contents of the firewall state table. Look over all the links in my previous reply, it's all explained there. It's not a WireGuard issue it's a fundamental aspect of stateful firewall behavior.
  • State of Wireguard package?

    6
    0 Votes
    6 Posts
    1k Views
    S
    @nomad0 said in State of Wireguard package?: I would love to know what the projected timeline for making this a production-worthy package is. pfSense package experimental do not mean underlying WireGuard is experimental. Please correct me someone if I'm wrong.
  • IOS client logs

    1
    1 Votes
    1 Posts
    674 Views
    No one has replied
  • Security of WireGuard

    2
    0 Votes
    2 Posts
    563 Views
    jimpJ
    OpenVPN isn't necessarily "constant" in that way, it occasionally has to renegotiate as well. WireGuard does not work the way you imply. It is for all intents and purposes connectionless. There may be a handshake but it's completely transparent. The VPN is always "active" and any packet that tries to use it will handle that negotiation in the background if it hasn't had a recent handshake and so on. There isn't any sense of it being "disconnected" where traffic would take some other path.
  • Connect to Wireguard from LAN side

    3
    0 Votes
    3 Posts
    573 Views
    S
    Ok, it's working now, I forgot to add a rule on the appropriate LAN interface to allow connections on the Wireguard port. I'm sorry about that.
  • WireGuard cannot access peer from UK to China

    4
    0 Votes
    4 Posts
    1k Views
    yon 0Y
    @knightzhang625 gfw blocked wireguard
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.