Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cant reach other LAN subnet via WG

    Scheduled Pinned Locked Moved WireGuard
    11 Posts 3 Posters 294 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      johnytb
      last edited by

      Hey
      My home LAN behind the ISP router is 10.100.102.0/24 .
      I have pfSense behind my ISP router in a LAN subnet 10.100.102.111 ( pfSense WAN )
      My pfSense LAN is 192.168.1.1
      My WG tunnel interface is 192.168.10.1

      I setup WG successfully and i can connect my WG interface tunnel from outside no problem. of course i port forwarding from ISP Router to the pfSense wan. I can reach all LAN's behind the pfSense from outside with no problem but i want also to reach my home LAN 10.100.102.0/24 .
      When im connected via WG i cannot reach my LAN subnet 10.100.102.0/24 - this LAN is behind the ISP router and NOT under the pfSense LAN's . I need to reach that subnet. What can i do ?
      I cannot ping or reach my ISP router via 10.100.102.1 and no other device in that subnet .

      please look at the uploaded image and follow the green arrow .
      thanks.

      wg.jpg

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @johnytb
        last edited by

        @johnytb
        You need to add an outbound NAT rule for the WG tunnel network.

        Firewall > NAT > Outbound
        Enable the hybrid mode and save it. Then add a rule with the WG tunnel subnet as the source and WAN address as translation address.

        J 1 Reply Last reply Reply Quote 0
        • J
          johnytb @viragomann
          last edited by

          @viragomann
          im not sure i understand where to add the rule? you mean in the outbound NAT ? or as a firewall rule ? please be more specific

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @johnytb
            last edited by

            @johnytb
            As I wrote, an outbound NAT rule.

            Check "Hybrid Outbound NAT" and save this.
            Add a rule:
            interface: WAN
            source: WG tunnel network
            destination: WAN net
            translation: interface address (WAN address)

            If you intend to route also interne traffic from the client over the VPN use "any" for the destination.

            J 1 Reply Last reply Reply Quote 0
            • J
              johnytb @viragomann
              last edited by

              @viragomann
              ok i added a rule excatly as you said and its not working

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @johnytb
                last edited by

                @johnytb
                Is the WAN subnet even routed over the VPN?

                J 1 Reply Last reply Reply Quote 0
                • J
                  johnytb @viragomann
                  last edited by

                  @viragomann
                  i can reach the firewall LAN's from outside if that what you asking...
                  but cannot "go back" to the WAN subnets ( my home LAN 10.100.102.0/24)

                  Bob.DigB 1 Reply Last reply Reply Quote 0
                  • Bob.DigB
                    Bob.Dig LAYER 8 @johnytb
                    last edited by

                    @johnytb Show how your WAN is configured in pfSense.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      johnytb @Bob.Dig
                      last edited by

                      @Bob-Dig
                      here is aa image of my wan interface configuration.

                      2c7cd190-b289-449d-971a-36724a6a954d-image.png

                      Bob.DigB 1 Reply Last reply Reply Quote 0
                      • Bob.DigB
                        Bob.Dig LAYER 8 @johnytb
                        last edited by Bob.Dig

                        @johnytb Why do you spoof MAC-address if you behind another router at home?
                        Outbound NAT is on automatic?

                        @johnytb said in Cant reach other LAN subnet via WG:

                        When im connected via WG i cannot reach my LAN subnet

                        Where are you if this happens? What is your WAN-IP on your device if this happens.

                        J 1 Reply Last reply Reply Quote 0
                        • J
                          johnytb @Bob.Dig
                          last edited by

                          @Bob-Dig
                          outbound nat is in Hybrid mode now.
                          dont understand the other questions..

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.