Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense CE after update to 2.7.2 wireguard site to site tunnels no longer work

    Scheduled Pinned Locked Moved WireGuard
    11 Posts 4 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bob.DigB
      Bob.Dig LAYER 8 @alfaro
      last edited by

      @alfaro I have two tunnels and on one I have seen similar. The only thing that worked was rebooting those pfSenses. And no problem since.

      A 1 Reply Last reply Reply Quote 0
      • A
        alfaro @Bob.Dig
        last edited by

        @Bob-Dig
        Thank you for the reply. Multiple reboots with no change in behavior to either unit

        J 1 Reply Last reply Reply Quote 0
        • J
          Jarhead @alfaro
          last edited by

          @alfaro Same thing happened to me on the 2.7.1 update.
          Had to recreate the tunnels. Couldn't find another fix.
          Weird thing was, 2 tunnels from CE to CE went down, the one tunnel from CE to pf+ still worked. So kinda the opposite of you but I would just rebuild the tunnels instead of wasting time.

          A Bob.DigB 2 Replies Last reply Reply Quote 0
          • A
            alfaro @Jarhead
            last edited by

            @Jarhead
            Thank you for your reply.

            So, just erase them and start from scratch? Did you use all the same info? same secrets/keys? same ip ranges and ports? or really just completely different?

            J 1 Reply Last reply Reply Quote 0
            • J
              Jarhead @alfaro
              last edited by Jarhead

              @alfaro I used all the same info. So copy the keys from both ends and use them to recreate the same tunnel.
              Came right back up for me.

              Also, I have interfaces assigned to all my tunnels and I didn't even have to touch them.

              1 Reply Last reply Reply Quote 0
              • Bob.DigB
                Bob.Dig LAYER 8 @Jarhead
                last edited by

                @Jarhead said in pfsense CE after update to 2.7.2 wireguard site to site tunnels no longer work:

                but I would just rebuild the tunnels instead of wasting time.

                I wanted to avoid that so I tried everything else first and last thing was a reboot. Maybe what I did before and the reboot together fixed it, don't remember anymore what I exactly did there.

                1 Reply Last reply Reply Quote 0
                • K
                  kryzmak
                  last edited by kryzmak

                  I have the same issue here and rebuilding the tunnels did not work (neither did rebooting). I run pfsense 2.7.2 as a virtual machine on proxmox v8 and since yesterday the peers are not connecting to my tunnel. It is very weird, because just one peer works and sometimes 2-3 other peers work temporarily. Until yesterday all worked well (the pfsense was on 2.7.1) and today I had these issues. Upgraded the pfsense to 2.7.2 but it did not solve the problem. Wireguard package is 0.2.1

                  PS: Packet Capture on WAN Interface shows incoming connections on wireguard port, but the pfsense just ignores that and does not response. The requests are dropped and not going through to the wireguard interface at all

                  K 1 Reply Last reply Reply Quote 0
                  • K
                    kryzmak @kryzmak
                    last edited by kryzmak

                    @kryzmak I found out that it is not working when I use dynamic endpoint on the failed pfsense

                    This configuration does NOT work for me anymore:

                    pfsense 2.7.2 with option "dynamic endpoint" ENABLED <----- pfsense 2.7.0 with option "dynamic endpoint" DISABLED

                    This configuration does work:

                    pfsense 2.7.2 with option "dynamic endpoint" DISABLED <----- pfsense 2.7.0 with option "dynamic endpoint" ENABLED

                    I assume that it has something to do with my setup here (pfsense as a vm on a proxmox 8 host) but I have no clue where to look for misconfiguration. Traffic on wan interface comes in but is not forwarded to the wireguard interface (when serving as a dynamic endpoint). Is there some kernel option missing?

                    For my static sites that is ok for now. But there are as well a lot of road warriors with non static ip addresses, so I have to use the pfsense as the dynamic endpoint and can not switch... Sorry, if my description is not understandable (but I hope so), non native english speaker here. ;-)

                    Bob.DigB 1 Reply Last reply Reply Quote 0
                    • Bob.DigB
                      Bob.Dig LAYER 8 @kryzmak
                      last edited by Bob.Dig

                      @kryzmak Maybe not the best idea to run different versions?

                      Anyway, I just noticed a problem. I changed one option on a remote pfSense CE (slow VPS) in WireGuard: I disabled to "Hide Peers". After this, I couldn't connect or ping this remote pfSense anymore from my pc. But my local pfSense+ still was pinging the remote gateway and reported everything would be fine. The only thing helped was rebooting this remote pfSense.

                      So I have the feeling that WireGuard isn't running that smooth anymore.

                      1 Reply Last reply Reply Quote 0
                      • K
                        kryzmak
                        last edited by

                        It seems to be an error specific for my setup here and not regarding pfsense/wireguard. I only have this problem at our provider colocation and not at our own locations.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.