Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Wireguard is not routing any traffic

    Scheduled Pinned Locked Moved WireGuard
    44 Posts 6 Posters 10.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User @Bob.Dig
      last edited by

      @bob-dig 1412 seems to work. Maybe you have to play a bit

      ? 1 Reply Last reply Reply Quote 0
      • ?
        A Former User @A Former User
        last edited by

        Solved my DNS problem. Looks like wireguard is not adding any routes. I had to add a manual one for the DNS-Address and the gateway

        Bob.DigB 1 Reply Last reply Reply Quote 0
        • Bob.DigB
          Bob.Dig LAYER 8
          last edited by Bob.Dig

          Got it working too, thanks for the MTU hint!!
          I went with 1420. Without it, it wasn't working.

          I didn't need any routes but my setup is different. Also no manual outbound NAT needed, see below.

          For IP I went with /32 and changed the IP for the second tunnel myself.
          ss.jpg

          1 Reply Last reply Reply Quote 1
          • Bob.DigB
            Bob.Dig LAYER 8
            last edited by Bob.Dig

            Something to note when using Surfshark VPN on pfSense with WireGuard instead of OpenVPN.

            You decide which IP will be used > no more overlapping IPs with different tunnels. 👍

            No good GUI support for changing the public IP of one tunnel, you have to restart the whole WireGuard service for all the tunnels to change IPs and it takes much longer for a new connection (but it is possible). 👎

            In my testing, speed was the same with my hardware.

            1 Reply Last reply Reply Quote 0
            • Bob.DigB
              Bob.Dig LAYER 8 @A Former User
              last edited by

              @thisisme I noticed that the performance is lower with WG on ss, more loss etc. What is your experience so far?

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @Bob.Dig
                last edited by

                @bob-dig I don't see any performance loss. Maybe even a little gain, but hard to say, because the last 15mbit to my full bandwidth are a bit unstable with Surfshark with both approaches.

                Bob.DigB 1 Reply Last reply Reply Quote 0
                • Bob.DigB
                  Bob.Dig LAYER 8 @A Former User
                  last edited by Bob.Dig

                  @thisisme Probem for me it is packet loss, not the speed. I kinda remember that even in their own app, WG is working worse then OVPN, so I will switch back... 😢 YGWYPF

                  ? 1 Reply Last reply Reply Quote 0
                  • ?
                    A Former User @Bob.Dig
                    last edited by

                    @bob-dig since 2 hours I have a lot of loss too. Since then it was always below 10%. I think the Surfshark servers are unstable or overloaded

                    Bob.DigB 1 Reply Last reply Reply Quote 0
                    • Bob.DigB
                      Bob.Dig LAYER 8 @A Former User
                      last edited by Bob.Dig

                      @thisisme Back on OVPN, so much better. It was a short endeavor. I think their WG implementation is just bad, for years now.

                      ? 1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User @Bob.Dig
                        last edited by

                        @bob-dig packet loss with WG close to zero again for me

                        Bob.DigB 1 Reply Last reply Reply Quote 0
                        • Bob.DigB
                          Bob.Dig LAYER 8 @A Former User
                          last edited by

                          @thisisme Maybe it was me ^^

                          1 Reply Last reply Reply Quote 0
                          • M
                            matosc
                            last edited by

                            My surfshark wireguard configuration is not working. I'm sure it must be something incredibly obvious, but I can't figure it out.

                            Can someone please scan the config below and let know what is missing. For testing I have it configured like @Thisisme 's example.

                            fyi .... I am using selective routing and have a couple of LAN devices that are configured with firewall rules to only route to the surfshark wireguard gateway. Also, my OpenVPN config is fine.

                            a2ac6108-6c78-4e14-b7f1-f5df114542a6-image.png

                            acedb5da-4cdd-4d5e-8546-8845852adc37-image.png

                            f8cb8907-8ac4-4f94-8785-0ee730bd534f-image.png

                            384edecd-4d15-4f41-b8f4-f6b81a9400e4-image.png

                            1c445a8d-42f8-4b27-8e16-87b240dece62-image.png

                            ef461375-218e-4411-b47f-516b13aea503-image.png

                            a81ef958-d26f-4a09-9ac8-4c8bd8bb08fb-image.png

                            054a7ec7-f282-4669-8c16-6bb1545264bb-image.png

                            Bob.DigB 1 Reply Last reply Reply Quote 0
                            • Bob.DigB
                              Bob.Dig LAYER 8 @matosc
                              last edited by Bob.Dig

                              @matosc Do you have two Gateways for that connection?

                              Today I noticed that pfSense isn't really doing any cleaning with gateways when I removed all OVPN connections and later removed all WG connections...
                              OVPN runs great with ss. I think it is even using DCO but I am not sure.

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                matosc @Bob.Dig
                                last edited by

                                @bob-dig I have several gateways, with only 1 for the wireguard connection.

                                1. WAN
                                2. Surfshark Wireguard
                                3. Surfshark OpenVPN - near my location
                                4. Surfshark OpenVPN - for USA connections

                                9447365b-8649-496e-b493-dfed7b4e768a-image.png

                                Helps?

                                Bob.DigB 1 Reply Last reply Reply Quote 0
                                • Bob.DigB
                                  Bob.Dig LAYER 8 @matosc
                                  last edited by

                                  @matosc Maybe you can't have two connections simultaneously (OVPN and WG) to the same server? I am back on OVPN so I can't help anymore.

                                  M 1 Reply Last reply Reply Quote 0
                                  • M
                                    matosc @Bob.Dig
                                    last edited by

                                    @bob-dig I really appreciate the help.

                                    I changed my config to test this more - recreated the wireguard configuration and removed the OpenVPN connections entirely.

                                    Still can't connect from the single device on the network that is configured with a LAN rule to only connect to the specified gateway.

                                    4199cc8b-6b4c-451e-83ae-c691827e0c1d-image.png

                                    Here is the latest config.

                                    478d3c3a-2604-4a79-a8aa-cd8a22af0262-image.png

                                    c95323e6-c34c-4413-b010-3adacb6ba67b-image.png

                                    9a6ac3ba-cc6d-4296-92f8-3b0eba68e61f-image.png

                                    25803738-db83-4f03-ad26-b50dbf859c3d-image.png

                                    e8796e49-577a-4966-8a44-14c174d4c914-image.png

                                    e21a06a6-6982-42a8-9c03-0093a108c43c-image.png

                                    fd524fff-7737-4dcd-817a-08e7ce3f15f7-image.png

                                    539cd277-4257-4bb6-bbc4-6383d971233e-image.png

                                    Bob.DigB 1 Reply Last reply Reply Quote 0
                                    • Bob.DigB
                                      Bob.Dig LAYER 8 @matosc
                                      last edited by Bob.Dig

                                      @matosc You could switch to Automatic Outbound NAT for now if you don't use OVPN.
                                      Have you given your public Key to ss in their WebUI?
                                      Your LAN rule has no fault?
                                      No rules on the WireGuard Group Interface, if it exist.

                                      I just got WG from pfSense to my android phone working, it took me ages... 🤢

                                      M 1 Reply Last reply Reply Quote 0
                                      • M
                                        matosc @Bob.Dig
                                        last edited by

                                        @bob-dig thanks for idea of turning on Automatic Outbound NAT. It's working! There must have been a hidden issue in the background. Anyway, I'm very happy that I can finally connect via WG.

                                        Everyone once and a while I lose WG connection and route via the WAN. This kinda sounds like what others are experiencing. Will track this topic and see if others report the same.

                                        1 Reply Last reply Reply Quote 0
                                        • Bob.DigB
                                          Bob.Dig LAYER 8
                                          last edited by Bob.Dig

                                          @Thisisme How is it going? How many WG-tunnels have you running with ss?

                                          ? 1 Reply Last reply Reply Quote 0
                                          • ?
                                            A Former User @Bob.Dig
                                            last edited by

                                            @bob-dig I have one tunnel atm. But I'm not sure about it. I have the same problem with OpenVPN and WG: several times a day I get packet loss leading to gateway shutdown. But with WG it seems more often.

                                            Bob.DigB J 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.