WireGuard as VPN server
-
Seems most of the discussion in this forum is regarding WireGuard as a client connecting to a VPN service provider.
I want to set up WireGuard as a server so remote clients can connect to my pfSense appliance to access the local subnet and the internet. I have not had any success. The remote peer is communicating with the pfSence tunnel (periodic handshake) but I am unable to get traffic to/from the subnet or internet.
Direction is appreciated. I can provide screen shots of the WireGuard config along with firewall stuff.
I am on pfSense 2.6.0-Development and WireGuard 0.0.9
Please advise.
Ted Quade -
This post is deleted! -
@tquade said in WireGuard as VPN server:
but I am unable to get traffic to/from the subnet or internet.
Do you have any rules on your Wireguard rules tab?
-
-
@tquade That rule isn't getting any hits. I don't know anything about the new wg config so I can't help you about that specifically but I remember some of the old on before it got pulled. Maybe you have something wrong in your config? Post screens with your keys obscured and maybe something obvious will appear.
-
@kom 2.6.0 isn't reporting state counts next to firewall rules...its been an ongoing bug for a long time in the 2.6 branch.
@tquade I would recommend trying a few things (all of which have been addressed internally and will be in the next release)
- If your clients are using Unbound, please create an Unbound ACL allowing your tunnel network. Services > DNS Resolver > Access Lists
- Clear your states and reload the filter
-
@theonemcdonald
Access lists did not resolve the matter.
Ted Quade
-
@tquade What does the allowed IPs look like on your server and your clients?
-
@theonemcdonald
Your question tickled the appropriate neuron. I had the wrong server ip address. Once corrected, access to the local subnet was established but no internet. I then went over to firewall outbound nat and noted that there were automatic rules for openvpn and ipsec but not for wireguard. I switched mode to hybrid, entered and saved the new rule and now have access to the internet.
Thanks for your help.
Ted Quade