• Odd routing / rules issue - contrary to setup guide

    1
    0 Votes
    1 Posts
    278 Views
    No one has replied
  • Unable to Establish Wireguard Connection Over Cell Network

    4
    0 Votes
    4 Posts
    928 Views
    rtorresR
    @emnul I don’t know if this was a typing mistake but I see form your post that your WG_TEST tunnel is listening to port 52821 and your iOS device is trying to connect to 51821. These should match for both Tunnel and Peer VPN Wireguard Tunnels: tun_wg1 Address / Assignment: WG_TEST Listen port: 52821 And your peer is: [Peer] pubKey = MY_PUB_KEY (i've confirmed it matches config in pfSense) Endpoint = MY_IP:51821 AllowedIPs = 0.0.0.0/0 You MUST have your WG_TEST (tun_wg1) Interface /24 and your Peers as /32. Based on the info you provided on your first post, this is how your WireGuard and Peer SHOULD look like: Tunnel Setup: VPN > WireGuard > Tunnels > Edit tun_wg1 Description: WG_TEST Listen Port: 51821 Interface Keys: [Auto-generated] Interface Setup: Interfaces > WG_TEST IPv4 Configuration Type: Static IPv4 IPv4 Address: 172.26.2.1/24 MTU: 1420 WAN Firewall Rules: Firewall > Rules > WAN Action: Pass Protocol: UDP Source: Any Destination: WAN Address Port: 51821 Firewall > Rules > WG_TEST Action: Pass Protocol: Any Source: WG_TEST Destination: Any Outbound (Hybrid Mode) Setup: Firewall > NAT > Outbound Interface: WAN Source Network: 172.26.2.0/24 Destination: Any Translation: WAN Address For Peer Config (in WireGuard): VPN > WireGuard > Peers Description: iOS Device Tunnel: WG_TEST Allowed IPs: 172.26.2.2/32 Endpoint: Dynamic On your iOS WireGuard App: [Interface] PrivateKey = [Auto Generated] Address = 172.26.2.2/24 DNS = 9.9.9.9 MTU = 1420 [Peer] PublicKey = [Auto Generated] PresharedKey = [Auto Generated] AllowedIPs = 0.0.0.0/0 Endpoint = WAN IP:51821 If you are still having an issue: This is the YouTube video I used to setup my WireGuard and it's been working flawlessly for 2+ years. How to Install WireGuard on pfSense (Tutorial) Follow it from start to finish in its entirety and set up as in the video. Made the mistake of cutting the video short thinking I was done but my WG was refusing to connect. I suggest you configuring all of the IPs as in the video to get an undertsanding and a working config, then modify as you like (with your desired 172.26.2.0/24 IPs).
  • Wireguard 0.2.9 - pfSense 24.11 - service issues since upgrade from 24.03

    6
    0 Votes
    6 Posts
    1k Views
    E
    @pfsenserich said in Wireguard 0.2.9 - pfSense 24.11 - service issues since upgrade from 24.03: I have confirmed if you reboot with wireguard up it crashes after reboot. have you tried stopping the wireguard service then rebooting and seeing if it comes up without errors? am not overjoyed at the fact I had to disable the daily cron reboots to stop this issue, but it is what it is. whats more troubling is the lack of replies to this thread. Will be opening a support ticket on this one eventually, just for Sh... an G..... I tried it. I stopped the WG service and restarted the PF Sense. But even so, I can only get the service to work again by reinstalling the Wiregard package.
  • pfSense CE Wireguard Throughput

    3
    2
    0 Votes
    3 Posts
    657 Views
    P
    @gguglielmi said in pfSense CE Wireguard Throughput: Does anybody knows if there's a difference between Plus and CE for Wireguard? Hardware encryption support is different
  • ProtonVPN

    3
    0 Votes
    3 Posts
    4k Views
    A
    @oddussiben-3161 The apparent lack of anything else (host route). I attempted to set up this configuration on an Ubuntu machine using Wireguard.
  • Specify parent interface for wireguard tunnel?

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • 0 Votes
    7 Posts
    1k Views
    P
    @LaUs3r When I check logs (status > system logs > firewall) and see nothing relevant. I edit names and all personnal info (giving names can lead to security breach. in my opinion)
  • Wierd firewall issue in wireguard

    3
    2
    0 Votes
    3 Posts
    454 Views
    D
    @Bob-Dig Allowed ips are 0.0.0.0/0 on both sides.
  • 0 Votes
    4 Posts
    946 Views
    A
    @Bob-Dig EDIT: Changing the default gateway under the "Routing" tab again caused the remote site to be inaccessible via the S2S VPN.
  • Connect 2 ipv4 sites through ipv6 wireguard tunnel

    5
    0 Votes
    5 Posts
    930 Views
    J
    @Bob-Dig Wonderful ! Much easier than I thought ! I just followed a tutorial which told me to do so. Thank you very much !
  • Wireguard Package re-install failing

    8
    0 Votes
    8 Posts
    2k Views
    M
    @BNetworker said in Wireguard Package re-install failing: I updated to 24.11. That resolved it. So, it appears the wireguard 0.2.9 package is incompatible with 24.03? This worked for me. would be nice if it warned, or did not let you update the package that isn't supported :(
  • Specify site to site MTU & MSS at one or both ends

    1
    2
    0 Votes
    1 Posts
    252 Views
    No one has replied
  • Wireguard Site 2 Site Tunnel not connecting

    9
    0 Votes
    9 Posts
    1k Views
    D
    Ohhh i forgot the gateway. Its working now. thank you so much.
  • Wireguard LAN ERR_TIMED_OUT

    1
    7
    0 Votes
    1 Posts
    246 Views
    No one has replied
  • Wireguard not starting

    12
    2
    0 Votes
    12 Posts
    1k Views
    L
    ok, maybe let's take a step back. You wrote that it works once you disable IPv6 in your WAN interface. Are you using IPv6 at all? If yes, have you configure IPv6 for your wireguard tunnel? Maybe it's worth checking out the video from Chris McDonald: https://www.youtube.com/watch?v=wYe7FzZ_0X8 Chris is the maintainer of the wireguard package for pfSense. In this video he shows the config for a wireguard tunnel for IPv4 AND IPv6
  • pfSense Wireguard Site-to-Site, routing issues??

    4
    1
    0 Votes
    4 Posts
    491 Views
    chpalmerC
    https://forum.netgate.com/topic/151871/solution-for-multicast-over-tunnel
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Setting up A Wireguard Tunnel For Dummies?

    3
    0 Votes
    3 Posts
    627 Views
    L
    @jmdomini , I shared some days ago my experience with wireguard in a step-by-step guide in this forum. Maybe that helps you. And please share some more info if it does not. screenshots are quite helpful
  • Unable to connect to devices on LAN

    6
    0 Votes
    6 Posts
    612 Views
    D
    @droidus Hello, I have a similar problem with setting up a new wireguard "client". Wireguard is running for a longer time with some clients connecting to home network. There are Androids and Linux Mint devices. All connect through a full tunnel. I added a new Linux Mint device. As always, same config (besides the keys...). The client is able to connect to pfsense, connect to the internet via tunnel BUT can't connect to any services hosted in my home network. Some important configs in my environment: Wireguard config file for my Linux Mint clients: [Interface] Address = 192.168.200.20/32 PrivateKey = 1234 DNS = 192.168.1.1 [Peer] PublicKey = 2222 PresharedKey = 3333 AllowedIPs = 0.0.0.0/0, ::/0 Endpoint = example.domain:51820 PersistentKeepalive = 15 -> DNS is my pfsense. DNS Resolver is enabled. No other DNS connection (e.g. 8.8.8.8) are allowed. Firewall logs show only connections to pfsense:53, to visited sites in the internet but no connections to local services in my home lan. I can't see any blocked packets of the attempt to connect . There are no states visible between any local service and the client. I even restarted pfsense. Any ideas what to check to fix this?
  • WireGuard pfSense 2.7.2 MobileData 0 received

    7
    7
    0 Votes
    7 Posts
    596 Views
    P
    @poldus My "thinking" of this PROBLEM are all KEYS (publics, privates and preshareds) are OK (because of handshaking OK) in both peers (Android, Windows) 2.. what else? rules? "default 51820 port (not working too) WireGuard is so "experimental" to me? so experimental that UNUSED from me?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.