Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [UnSolved] Possible BUG : Wireguard routing weirdly

    Scheduled Pinned Locked Moved WireGuard
    30 Posts 3 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • arrmoA
      arrmo
      last edited by

      @AB5G BTW, are you finding that a pass-all rule on the WireGuard group does help any, or not at all? I find it helps, but it's not a fix-all. Still some issues.

      I checked the firewall logs, nothing there noted as blocked, so fun to debug. Any suggestions? Enabled logging on default rules? Or try tcpdump? To try to help resolve this.

      Thanks!

      A 1 Reply Last reply Reply Quote 0
      • A
        AB5G @arrmo
        last edited by

        @arrmo No it doesn't work for me. The packet passes the WG filter, get Natted to the WG Tunnel IP and then gets lost - I don't see it on the WAN.

        arrmoA 1 Reply Last reply Reply Quote 0
        • arrmoA
          arrmo @AB5G
          last edited by

          @ab5g Dang it! And you have WireGuard set like this, right?
          16c74a0f-74cd-42d8-aeab-dee9d2c05d58-image.png

          This is matching to what you recommended to me, so assuming you do - but just in case. Once I do this, and set up Hybrid Outbound NAT, then things are better (not 100%, but a lot better). Using the WG Interface causes me all sorts of grief 😞

          Thanks!

          1 Reply Last reply Reply Quote 0
          • arrmoA
            arrmo
            last edited by arrmo

            @AB5G Please let me know if you have any luck. Had to tear down WireGuard, go back to OpenVPN. Just not finding it up / consistent enough. Dang it! I see the (good) potential though 👍

            Thanks!

            BTW, this isn't perhaps the split routing that OpenVPN uses (on the "client" side), is it? Or are you not redirecting all traffic?

            A 1 Reply Last reply Reply Quote 0
            • A
              AB5G @arrmo
              last edited by

              Nope no luck and no one else is reporting this issue so I'm holding still.

              arrmoA 2 Replies Last reply Reply Quote 1
              • arrmoA
                arrmo @AB5G
                last edited by

                @ab5g Understood, here as well. Just yell if there is anything I can do to help!

                1 Reply Last reply Reply Quote 0
                • arrmoA
                  arrmo @AB5G
                  last edited by

                  @ab5g FYI, I'm not seeing any more odd routing issues - now that I am on v2.5.0 (vs. RC I was running before). Are you on 2.5.0, and still seeing issues? If not, perhaps give it a try?

                  A 1 Reply Last reply Reply Quote 0
                  • A
                    AB5G @arrmo
                    last edited by

                    @arrmo Yeah still there - I've made my peace with it though. Its only my AppleTv that routes through the VPN, so whenever things don't work - I find out the IP address of what the TV is trying to access and add it to the Wireguard peer. Because its is only a few apps on the TV - its not much hassle to add add the IP blocks once in a while.

                    arrmoA 1 Reply Last reply Reply Quote 1
                    • arrmoA
                      arrmo @AB5G
                      last edited by

                      @ab5g OK, NP - just figured I'd let you know. BTW, are you adding the pass rules to the interface, or the WireGuard (group)? I'm still using the group, never did get the interface working 😞.

                      Thanks!

                      A 1 Reply Last reply Reply Quote 1
                      • A
                        AB5G @arrmo
                        last edited by

                        @arrmo Im using the interface. For now leave it to whatever is working for you. When things calm down around the new release maybe we can revisit this with the devs.

                        arrmoA 1 Reply Last reply Reply Quote 1
                        • arrmoA
                          arrmo @AB5G
                          last edited by

                          @ab5g Sounds good, thanks!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.