Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Weird issue with certain traffic "dissapearing" when going in wireguard tunnel

    Scheduled Pinned Locked Moved WireGuard
    wireguardvpnnatrulesportforward
    3 Posts 2 Posters 111 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      DonZalmrol
      last edited by DonZalmrol

      Hi all,

      So I got a weird issue going and I can't figure it out and keeps me going in circles.
      I have a Pfsense firewall hosted in Hetzner cloud and my home lab firewall with Opnsense. The WG is working fine (AFAIK) and allows traffic from my FW to my home lab servers and services (e.g. http, https, snmp, ...) but when I try to route SMTP 25 it simply isn't going through the tunnel.

      I've created an example network drawing.
      Network home-hetzner.jpg

      What works without any issues?

      • Hetzner Pfsense (240.0.0.1) with HAProxy to my homelab opnsense (224.0.0.1) -> homelab webserver 192.168.0.10

      • Same for mailserver 1 and 2, librenms can retrieve SNMP (161) from Hetzner Pfsense firewall

      • Hetzner WAN -> Spamserver (192.168.128.3) -> Port 2500 to Mailserver 1 (Exchange)

      What doesn't work:

      • Hetzner WAN (240.0.0.1) -> Portwarding -> Port 25 TCP to Mailserver 2 (Mailcow)
      • Hetzner WAN - Floating IP (250.0.0.1) -> Portwarding -> Port 25 TCP to Mailserver 2 (Mailcow)

      When I do a direct test port on Pfsense to my mailcow = success, I receive the EHLO back
      When I test the mailserver through MXtoolbox it fails :(
      2025-05-26_15h33_43.png

      It's like it takes the traffic and then does not forward it. The state is in CLOSED:SYN_SENT and the bytes incoming is increment, yet the outgoing is always 0, example below
      2025-05-26_15h27_39.png

      All static routes are in place on both sides and the tunnel network is 172.16.0.8/30, all other traffic seems to be working. It's driving me nuts!

      EDIT: Yes, SMTP is allowed on the Hetzner VMs :)

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @DonZalmrol
        last edited by

        @DonZalmrol It should work if you haven't made any mistake. 😉

        D 1 Reply Last reply Reply Quote 0
        • D
          DonZalmrol @Bob.Dig
          last edited by

          @Bob-Dig yeah lol, but I'm pretty sure I've followed everything to the letter as the other services are working or it's something small I'm overlooking....

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.