Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    no handshake unless psk is used

    Scheduled Pinned Locked Moved WireGuard
    11 Posts 2 Posters 255 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sneakynuts
      last edited by

      Hi All
      Have just configured a new phone as another peer
      I set up everything as i have done previously

      However, this new peer wont connect unless i use a pre-shared key - As soon as i enter the psk, i can see the handshake and peer active
      My other 2 peers dont use a psk and they connect just fine

      Anything obvious that would cause this or i can check?

      Cheers

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @sneakynuts
        last edited by

        @sneakynuts said in no handshake unless psk is used:

        My other 2 peers dont use a psk and they connect just fine

        PSK is a per peer setting. You must have set a PSK on one side already, it wouldn't work otherwise.

        1 Reply Last reply Reply Quote 0
        • S
          sneakynuts
          last edited by

          maybe im missunderstanding then.
          On both peer and pfsense, i have left the Pre-Shared Key (optional) field blank

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB
            Bob.Dig LAYER 8 @sneakynuts
            last edited by

            @sneakynuts Show all the configs of all sides of that problematic tunnel.

            1 Reply Last reply Reply Quote 0
            • S
              sneakynuts
              last edited by

              S25 peer is the one im having issues with.
              pfsense side Screenshots:
              c7b03db9-52bc-4f47-b3b5-b45c050571f7-image.png
              pfsense peer.png

              From S25
              s25 wg.jpg

              Bob.DigB 1 Reply Last reply Reply Quote 0
              • Bob.DigB
                Bob.Dig LAYER 8 @sneakynuts
                last edited by

                @sneakynuts Makes no sense, that a PSK would be needed here. All your endpoints have private addresses? Try to replace MTU from 1420 to 1280.

                1 Reply Last reply Reply Quote 0
                • S
                  sneakynuts
                  last edited by

                  Yes, all peers use the same endpoint, which is my static IP
                  I will try mtu change now

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • Bob.DigB
                    Bob.Dig LAYER 8 @sneakynuts
                    last edited by

                    @sneakynuts And don't use 10.10.10.* on pfSense, this range is used by pfBlocker.

                    1 Reply Last reply Reply Quote 0
                    • S
                      sneakynuts
                      last edited by

                      No difference if i set the mtu.

                      I'll change the ip to 10.0.0* range

                      1 Reply Last reply Reply Quote 0
                      • S
                        sneakynuts
                        last edited by

                        So, i have changed pfsense to 10.0.0.1
                        Galaxy Tab - 10.0.0.3
                        S25 - 10.0.0.5

                        Galaxt tab works, S25 does not

                        1 Reply Last reply Reply Quote 0
                        • S
                          sneakynuts
                          last edited by

                          any other suggestions on what might be the issue?
                          Cheers

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.