• Wireguard failing to save/create peer

    2
    0 Votes
    2 Posts
    973 Views
    CreationGuyC
    I fixed it, it was my mistake. For those of you who may come across this, here's what I did wrong: I set the listen port for both tunnels to be the same, if I had read all of the documentation, I would have known that they need to be unique... :)
  • Wireguard endpoint tunnel state offline.

    1
    0 Votes
    1 Posts
    398 Views
    No one has replied
  • WG 0.1.5 / pfS+ 21.05.1 - 2 WAN→1 WAN failover, not "failing back"

    16
    0 Votes
    16 Posts
    4k Views
    luckman212L
    @ddbnj Feel free to fork and modify it- I had a "StateKiller" package that I was working on to do more complex rule-based state killing / failback but I sadly never finished it. Not sure how much interest there is for that now that they added some more general purpose state killing options in the recent builds.
  • Tunnel in tunnel design questions

    1
    0 Votes
    1 Posts
    374 Views
    No one has replied
  • WireGuard multiple fail over and dynamic routing

    7
    0 Votes
    7 Posts
    1k Views
    O
    @luckman212 it's the same as a non bgp peer. setup bgp router options [image: 1664907772561-306a917e-13c2-44c5-8a5a-8cfada76f504-afbeelding.png] [image: 1664907793482-4f5593a5-9d1c-408b-a111-e3ff89537a9f-afbeelding.png] neighbour (target system) [image: 1664907838085-3b7f143a-26aa-4a7d-a80b-b84b9f133790-afbeelding.png] [image: 1664907879262-d72ded88-c449-4839-8cd0-86b5dcd303d9-afbeelding.png] You need to setup frr [image: 1664908023563-b943ce1a-0a31-4ebc-a4ac-6cd092f300c9-afbeelding.png] [image: 1664907980899-565fac11-b6dd-4103-8f12-0e12cd5a75ef-afbeelding.png] That's the allow all on the bgp And setup ofcourse interface and firewall rules
  • Block Wireguard site-to-site traffic via a certain WAN?

    2
    1 Votes
    2 Posts
    628 Views
    luckman212L
    This is the best I could come up with for now. It's a pair of floating rules (block/quick) one for each direction (in/out). In the screenshot below, n_coresite_ext is an IP alias of the far end static IP/subnet, 51828 is the listen port on the far-end tunnel, and WAN2_RUT is my failover WAN interface (the one I do not want any WG traffic to traverse). It also helps to have wgfix.sh (github) installed. [image: 1664895848013-dbb94a9c-5fe3-47c5-96d1-cd94ce605a2b-image-resized.png]
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • WireGuard with IPv6 SLAAC Addresses?

    14
    1 Votes
    14 Posts
    5k Views
    luckman212L
    @sgc would also love to know the quick details (dont need a super detailed writeup) of how you got your WG remote access tunnel set up with SLAAC or DHCP6
  • 0 Votes
    5 Posts
    4k Views
    T
    @cmcdonald thank you for the explanation. indeed the problem was my frr configuration, all is working fine now.
  • TLS Handshake failed fragmentation issue?

    3
    0 Votes
    3 Posts
    1k Views
    C
    After really long try and error I found the cause of all the mess. It is in this case mandatory to enter a MSS into the wireguard interface. I thought its calculated automatic based on MTU so 1420 - 40 = 1380. but it is not! After entering the MSS (1380) the connection is working like charm, also with large packets and hardware offloading.
  • Allowed IP in peers question

    1
    0 Votes
    1 Posts
    365 Views
    No one has replied
  • Wireguard is not routing any traffic

    44
    0 Votes
    44 Posts
    12k Views
    Bob.DigB
    @JeGr Apropos living on the edge. [image: 1663510391633-screenshot-2022-09-18-161302.png]
  • Any new info on wireguard in HA/CARP setup?

    1
    0 Votes
    1 Posts
    423 Views
    No one has replied
  • WireGuard upload speeds slow after latest updates

    1
    0 Votes
    1 Posts
    458 Views
    No one has replied
  • Poor Client Performance Across Wireguard Site-to-Site Tunnel

    6
    0 Votes
    6 Posts
    1k Views
    W
    Update - Running iperf3 on Windows and setting the "-w" flag to "1m" gets me closer to ~450Mbs. Now I've got to figure out how to get windows to do that by default...
  • 0 Votes
    5 Posts
    1k Views
    L
    So, after some further digging, I discovered a couple things. You have to actually assign the tunnel to an interface The MacOS Wireguard app doesn't support .ddns.net domains Thank you for your help, once I assigned the interface correctly everything worked like a charm.
  • Wireguard Issue with multi WAN

    1
    1 Votes
    1 Posts
    440 Views
    No one has replied
  • Surfshark WireGuard - Traceroute not working

    1
    0 Votes
    1 Posts
    477 Views
    No one has replied
  • Can't connect to Wireguard server from WAN

    5
    0 Votes
    5 Posts
    830 Views
    V
    @bob-dig It works! Thanks!
  • Cannot connect to LAN devices from Wireguard VPN

    6
    0 Votes
    6 Posts
    6k Views
    J
    @ben9090 Good that it's working but if you want to troubleshoot the pings, do packet captures on all relevant ports to see where they're getting lost.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.