WG Site2Site issues
-
Hello,
due to massive performance issues when using SMB over IPSec I tried Wireguard Site2Site.Tunnel is up, icmp is working fine.
I used for testing a IPv4* * * rule.But traffice beside icmp is not possible, I get massive blocks on the WG-Interfaces:

Even when setting the rule to Any flags - sloppy state it doesn't work.
I'm very confused right now.
-
Hello,
it's a standard rule to block:pfctl -vvsr |grep 1000000101 @6 block drop in quick inet from 169.254.0.0/16 to any label "Block IPv4 link-local" ridentifier 1000000101 -
@Bronko
The command output of pfctl -vvsr | grep 100000101 is:
@2 block drop in log inet all label "Default deny rule IPv4" ridentifier 1000000101But as I have a rule above saying allow any, this shouldn't happen!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.