• WireGuard site-to-site pfsense-to-pfsense no handshake?

    42
    0 Votes
    42 Posts
    14k Views
    cmcdonaldC
    @bassopt Take another peak now, updated package should be available. https://files01.netgate.com/pfSense_v2_5_2_amd64-pfSense_v2_5_2/All/pfSense-pkg-WireGuard-0.1.5_3.txz
  • Cannot Connect to 1x Specific Host Through WireGuard

    18
    0 Votes
    18 Posts
    2k Views
    A
    @dma_pf Good call! I'll try it. Thank you so much for your help.
  • Another slightly different 'unable to update' problem

    Moved
    4
    0 Votes
    4 Posts
    3k Views
    J
    @securvark I had the same issue. This worked for me as well. Thanks for posting.
  • How to secure home side of site to site VPN

    4
    0 Votes
    4 Posts
    987 Views
    AndyRHA
    @mooncaptain You only need the rules on one interface for each FW. Sounds like you are good to go.
  • Setting up site to site example - can't edit peer

    1
    0 Votes
    1 Posts
    433 Views
    No one has replied
  • Problem using internal web server port 443

    2
    0 Votes
    2 Posts
    818 Views
    M
    Well after these whole hours I might say that the issue can be on the HAProxy side, but I cannot say why ... HAproxy is configured to the WAN IP on port 443/80. If I disable the HAproxy I can connect to the web servers, but not if HAproxy is enabled. Why? Shouldn't the 'routing' between the LAN and VPN interfaces be dealt with without passing thru the WAN? It seems that traffic goes to WAN ... and is being intercepted by the HAproxy . I'm confused .. or I'm missing a big issue in here ... JG
  • Mullvad indicates leaking DNS servers

    2
    0 Votes
    2 Posts
    1k Views
    mooncaptainM
    @mooncaptain Answering my own question: All devices that use DHCP have No leaks. In windows I check the connection details with ipconfig/all and that shows that the Mallvad DNS servers are pulled in. My problem was with a statically configured workstation. For that I have to manually spec the DNS servers. All is good - so far - since I am going to start messing around with the configuration to test fail over.
  • Hiding Home Network traffic from ISP Tracking

    13
    0 Votes
    13 Posts
    3k Views
    provelsP
    @gertjan In the US, data is dollars and sold to the highest bidder. Governance optional.
  • WireGuard Interface no available on 'Interfaces' selection

    7
    0 Votes
    7 Posts
    2k Views
    M
    @mooncaptain and @dma_pf Thank you !! After reading your previous reply, ( and after having removed the WireGuard package, with the option not to save the previous configurations ). I reinstalled the package, and the first thing I did was, as mentioned by @mooncaptain, I went to the 'Settings' tab on the package, and enable it. I tried to do that on the previous attempt but was unable to do that. After doing that, I created the tunnel and checked to see if it appears on the selection on the interface, and this time it did !. I must have done something right when removing the package, without any previous settings. BTW, I didn't reboot the FW, as I have an offsite backup running that cannot be interrupted at this time. So this time I can select and assign the interface! Thank for the video, I'm going to watch it before I continue with this setup. I'll update this after that finishes. Thanks again. JG
  • Errors with WireGuard site to site connection

    1
    0 Votes
    1 Posts
    594 Views
    No one has replied
  • pfsense freezes if wireguard is installed!?

    1
    0 Votes
    1 Posts
    595 Views
    No one has replied
  • Install wireguard package got error message.

    3
    0 Votes
    3 Posts
    1k Views
    A
    Ok,I got it.I will upgrade it.
  • Always show Address is already configured on this firewall.

    1
    0 Votes
    1 Posts
    530 Views
    No one has replied
  • WG not routing or sending traffic

    44
    0 Votes
    44 Posts
    14k Views
    X
    @xxgbhxx Just thought I'd do a very quick update. It happened to me again today and I've finally nailed EXACTLY what the issue was/is and it turns out it was an already known issue with VMWare/PfSense (gee thanks Netgate). The issue is with VMWares allocation of NIC's. In VMware when you add new nics they number them vmx0 vmx1 vmx2 and so on. When you add a new card for some completely inexplicable reason, VMWare numbers the NEW card vmx0 and then bumps up the interface numbers of all the other cards (so what WAS vmx0 becomes vmx1). This immediately breaks pfSense and pretty much means you have to re-do all your interfaces and firewalls. SO The moral here is add as many interfaces from day one as you ever expect to use and if you DO decide to any later on, make sure you fully prep for the impact (because remembering interface names/locations from 9 months ago is not easy!) Thought I'd leave this here in case anyone has the same issue.
  • WireGuard in pfSense 2.5 Performance

    47
    5 Votes
    47 Posts
    11k Views
    H
    @jwt is/was this reply intended for someone else?
  • undesired NAT translation over wireguard tunnel

    11
    1 Votes
    11 Posts
    2k Views
    T
    Ahhh! This explains so much! I had tried to copy my existing rules across from IPSEC tunnels to Wireguard and it just wasn't working like I expected. I hadn't considered the gateway interface was doing NAT - make sense I guess when you think about it. Switching to Manual Outbound NAT and then disabling the WireGuard interface fixed it. This really gets pretty messy when you're doing multiple site to site IPSEC migrations to wireguard (I was having poor performance using IPSEC / Starlink for what ever reason - Wireguard just seemed to work) Can anyone recommend a pfsense / Wireguard guru that would we available to look over a proposed setup and provide best practice? Happy to pay - Id rather do it once correctly than introduce unnecessary workarounds and fixes to get it going. approx 20 sites, DC, Azure (pfsense)
  • WireGuard RoadWarrior Setup not even a handshake

    2
    9
    0 Votes
    2 Posts
    506 Views
    No one has replied
  • Repetitive "loop detected" in WireGuard interface

    4
    1 Votes
    4 Posts
    2k Views
    J
    I had the same issue. I configured the wireguard interface as an actual IP interface and the issue cleared up.
  • pfSense 2.5.2 - New Fresh Guaranteed WIREGUARD

    1
    0 Votes
    1 Posts
    771 Views
    No one has replied
  • WG Sporadic, TCPDUMP question.

    2
    0 Votes
    2 Posts
    881 Views
    DIYsenseD
    I've hit a roadblock here. Is there somebody who can offer a bit of advice?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.