• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WireGuard site-to-site pfsense-to-pfsense no handshake?

Scheduled Pinned Locked Moved WireGuard
42 Posts 7 Posters 11.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bassopt
    last edited by Aug 11, 2021, 3:10 AM

    This was working fine on version 0.1.3. Updated to 0.1.5 and now I cannot access any of my peers subnet defined in static routing. I can ping from pfsense but pinging from any address on the lan subnet doesn’t work. Site one can’t ping site 2 and vice versa.

    T 1 Reply Last reply Aug 14, 2021, 5:53 PM Reply Quote 0
    • T
      titansilber @bassopt
      last edited by Aug 14, 2021, 5:53 PM

      With hybrid nat the automatic nat rules for the WG interface look like a hot mess, especially if you have multiple interfaces. Anyone have examples of what it should look like?

      M 1 Reply Last reply Aug 18, 2021, 9:36 AM Reply Quote 0
      • M
        Mikki-10 @titansilber
        last edited by Aug 18, 2021, 9:36 AM

        @titansilber

        What is your goal with the Outbound NAT change? It is not required for site-to-site.

        If the goal is to change all traffic to the interface ip you can do that by setting to roules:

        Interface: WG interface
        Source: 127.0.0.0/8
        Source port: *
        Destination: * or what you need
        Destination port: *
        NAT Address WG address
        NAT port: *
        Static port: false

        Interface: WG interface
        Source: <Your LAN ip
        Source port: *
        Destination: * or what you need
        Destination port: *
        NAT Address WG address
        NAT port: *
        Static port: false

        Not sure if this is what you are looking for?

        B 1 Reply Last reply Aug 18, 2021, 5:49 PM Reply Quote 0
        • B
          bassopt @Mikki-10
          last edited by Aug 18, 2021, 5:49 PM

          After much hair pulling I finally made this work and stable.

          You need to specify / create and assign he gateway to the WG Interface when you create it else you'll have or sort of routing issues
          You also need to create static routes to the gateway with the subnets you want to access on the other side of the tunnel.

          Oh and the instructions above are wrong the Gateway ip needs to be the ip of tunnel on your side and not on the opposite side or it won't work.

          Unfortunately then entire wireguard project seems to be quite secondary at this point for negate (they didn't even bothered updating the documents)... I know it's still experimental, but ok...
          The developer is also never available never replies to anything in any of the platforms he mentions on his videos. He just ignores 99% of problems people are having (I hope they are not expecting us to start opening pointless stuff on redmi)

          M 1 Reply Last reply Aug 25, 2021, 12:40 PM Reply Quote 0
          • M
            Mikki-10 @bassopt
            last edited by Aug 25, 2021, 12:40 PM

            @bassopt

            Hi the use of the Gateway ip from the other side is not wrong, you do that with OpenVPN site to site as well when using layer 2 (TAP interface) and it give you the correct ping to the other side, and it helps keep the connection/session alive.

            You do not need to do any NAT config if you follow the above.

            Just remember to set the
            MTU: 1420 and
            MSS: 1420
            That fix most problems.

            1 Reply Last reply Reply Quote 0
            • B
              bbrendon
              last edited by Oct 18, 2021, 6:32 PM

              there is also a bug here that causes no handshake.
              https://forum.netgate.com/topic/167279/wireguard-won-t-handshake-package-bug?_=1634581891833

              C 1 Reply Last reply Nov 10, 2021, 10:07 PM Reply Quote 0
              • C
                cmcdonald Netgate Developer @bbrendon
                last edited by Nov 10, 2021, 10:07 PM

                This bug should be resolved in the latest version (0.1.5_2 and above). This package is available CE 2.5.2/2.6.0 and Plus 21.05.2/22.01. Give it a shot :)

                Need help fast? https://www.netgate.com/support

                B 1 Reply Last reply Nov 10, 2021, 10:20 PM Reply Quote 0
                • B
                  bassopt @cmcdonald
                  last edited by Nov 10, 2021, 10:20 PM

                  @cmcdonald I don’t see any 0.1.5_2 update on my end

                  C 2 Replies Last reply Nov 10, 2021, 11:13 PM Reply Quote 0
                  • C
                    cmcdonald Netgate Developer @bassopt
                    last edited by Nov 10, 2021, 11:13 PM

                    @bassopt hmmm, will check the builds. Thanks for checking

                    Need help fast? https://www.netgate.com/support

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmcdonald Netgate Developer @bassopt
                      last edited by Nov 15, 2021, 6:04 PM

                      @bassopt Take another peak now, updated package should be available.

                      https://files01.netgate.com/pfSense_v2_5_2_amd64-pfSense_v2_5_2/All/pfSense-pkg-WireGuard-0.1.5_3.txz

                      Need help fast? https://www.netgate.com/support

                      1 Reply Last reply Reply Quote 1
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received