Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. wireguard
    Log in to post
    • All categories
    • H

      Wireguard and 23.01

      WireGuard
      • wireguard releases • • hendryjl
      5
      0
      Votes
      5
      Posts
      158
      Views

      H

      @jimp Thank you! Sorry I didn't run across this in my reviews of other forums. That was EXACTLY what I was looking for!

    • P

      Strange login from another country

      WireGuard
      • wireguard • • pastic
      5
      0
      Votes
      5
      Posts
      198
      Views

      P

      @bob-dig said in Strange login from another country:

      @pastic said in Strange login from another country:

      I realise something as I write this: are there 'two levels' involved here? The wireguard rule will let everyone through the firewall on the specified port, but having passed the firewall block then the wireguard service will still refuse everyone that does not have the configured keys?

      Yes. Hard to believe that this is news to you, you are setting up a graylog server, which is advanced stuff in my book.

      Let's call it a blind spot. :-) I don't work with networks, it's just a hobby. And until this Wireguard 'project' I always had pfsense blocking everything from the outside.
      And yes, I did struggle a bit setting up graylog, but it was fun.
      Thanks!

    • P

      Strange Wireguard login from privatealps.net in another country

      General pfSense Questions
      • wireguard • • pastic
      1
      0
      Votes
      1
      Posts
      90
      Views

      No one has replied

    • F

      Setting up ProtonVPN on homebuilt pfSense router

      OpenVPN
      • protonvpn wireguard vpn connection • • F4 0
      2
      0
      Votes
      2
      Posts
      538
      Views

      G

      first, try openvpn because that is well established and wire guard is new. the ProtonVPN service website should have setup instructions and OpenVPN config files that you can use.

    • F

      Configuration vpn wireguard

      WireGuard
      • wireguard • • fnava92
      1
      0
      Votes
      1
      Posts
      120
      Views

      No one has replied

    • R

      Wireguard Site to Site

      WireGuard
      • wireguard site-to-site • • random_pawn
      7
      0
      Votes
      7
      Posts
      156
      Views

      R

      @jarhead

      I am configuring this device for deployment. Sorry I was not clear on that point. That is why the WAN is connected to my LAN. This device will be going over a thousand miles away and I need to set it up before it makes that journey. All of this headache just so I can remotely help (and make my life a little easier without needing to coordinate some kind of remote desktop/access). And this scenario requires the remote device to punch the hole through because their ISP uses private IPs, so the link will rely on the remote device establishing the link.

      I have isolated it to the Firewall blocking the access. The default deny rule was stepping in to block it. The Firewall knows it is the S2S interface... and not the WAN. Private IP restrictions do not apply. The Default deny rule on both firewalls was blocking access. Oddly, the PC on the remote pfSense had no issues accessing my pfSense WebGUI but could not access my LAN devices... and I could not go the other direction to access the WebGUI of the remote device..

      I need to review the syntax/scope on the Firewall rules again. By default, pfSense uses XXX net for Source. I had copied the allow rules to the S2S interface and updated to use S2S net. As Christian's video shows in the Firewall section, source is set to * (All). I have the tunnel working now. So sorry about wasting anyone's time.

      P.S. Akismet is flagging my post as spam. Not sure why that is. Apparently it won't allow me to add images with the post.

    • J

      GRE tunnel question

      IPsec
      • gre gif wireguard routing • • jbeez
      1
      0
      Votes
      1
      Posts
      238
      Views

      No one has replied

    • T

      Option to disable wireguard adding routes (Table = off)

      WireGuard
      • frr wireguard route default route bgp • • trunet
      5
      0
      Votes
      5
      Posts
      472
      Views

      T

      @cmcdonald thank you for the explanation. indeed the problem was my frr configuration, all is working fine now.

    • V

      wireguard multiwan doesnt properly round robin traffic

      Routing and Multi WAN
      • wireguard multiwan traffic shaping • • Viss
      1
      0
      Votes
      1
      Posts
      214
      Views

      No one has replied

    • L

      DNS Resolution of server failing... but I can ping the box?

      WireGuard
      • dns resolution firewall rules wireguard • • lukeclover21
      5
      0
      Votes
      5
      Posts
      349
      Views

      L

      So, after some further digging, I discovered a couple things.

      You have to actually assign the tunnel to an interface The MacOS Wireguard app doesn't support .ddns.net domains

      Thank you for your help, once I assigned the interface correctly everything worked like a charm.

    • L

      DNS Resolution for Wireguard tunnel failing

      DHCP and DNS
      • dns firewall rules wireguard dns resolution • • lukeclover21
      3
      0
      Votes
      3
      Posts
      549
      Views

      L

      @bob-dig Yes, I can ping the domain name and receive a response from the firewall.

    • G

      Wireguard Routing Problems - Help wanted

      General pfSense Questions
      • wireguard routing assymetric vpn • • gelcom
      10
      0
      Votes
      10
      Posts
      287
      Views

      G

      @stephenw10 I deleted the WireGuard tunnel then I set it up all over again. Done the same thing at VPS. Rebooted remote VM and pfSense and it started working.

      I have no idea what happened before but I thanks you for all the support you provided!!

      Thanks a lot

      :-)

      kind regards

    • D

      Wireguard.com SSL problem.

      WireGuard
      • wireguard • • DrPeterVC
      8
      0
      Votes
      8
      Posts
      348
      Views

      D

      @johnpoz

      Thanks - but that gave the same error. I think the root of my problem is that VirginMedia hate VPNs!

      https://windowsreport.com/vpn-blocked-virgin/

      I think I will try accessing the site sometime when on another isp!

      Thanks again - must go battery very low.

    • M

      How do you direct all traffic from a remote Wireguard peer through my pfsense SG5100

      WireGuard
      • wireguard allowed ip • • munson
      13
      0
      Votes
      13
      Posts
      664
      Views

      G

      @munson any update?

    • luckman212L

      Possible to shape NFS traffic?

      Traffic Shaping
      • shaper shaping qos vpn wireguard • • luckman212
      2
      0
      Votes
      2
      Posts
      366
      Views

      luckman212L

      I created a small tool luckman212/stv to help make it a little easier to debug states. In case it's useful to anyone else.

    • M

      MTU question with MultiWan/OpenVPN/Wireguard

      Routing and Multi WAN
      • mtu mss multiwan wireguard openvpn • • murdof
      1
      0
      Votes
      1
      Posts
      328
      Views

      No one has replied

    • M

      Route Wireguard traffic through Squid Proxy

      Traffic Monitoring
      • wireguard vpn squid proxy • • ma0f97
      2
      0
      Votes
      2
      Posts
      835
      Views

      M

      @ma0f97 Has no one an idea?

    • S

      WireGuard site to site tutorial

      WireGuard
      • wireguard site-to-site • • stepanov1975
      1
      0
      Votes
      1
      Posts
      363
      Views

      No one has replied

    • F

      WireGuard Asymetric NAT Issue when port forwarding from external server

      WireGuard
      • pfsense 2.6.0 wireguard nat routing • • flewid
      2
      0
      Votes
      2
      Posts
      888
      Views

      F

      For anyone else finding this thread. I've found the solution.

      Create a port forwarding rule

      INTERFACE: WG0
      PORT: 44158
      DESTINATION: WG0
      DEST PORT: 44158
      REDIRECT TARGET IP: MINER IP
      REDIRECT PORT: 44158

      Then everything works as expected.

    • B

      WireGuard multiple client bug

      pfSense Packages
      • wireguard • • bbusa
      20
      0
      Votes
      20
      Posts
      1410
      Views

      B

      @jimp thx for the hint it's working now, it totally make sense now. hope it will you @bbusa as well

    • A

      Wireguard Public and Private Key Protection

      WireGuard
      • wireguard • • aakashjonwal
      6
      0
      Votes
      6
      Posts
      738
      Views

      P

      @theonemcdonald said in Wireguard Public and Private Key Protection:

      I have mentally considered an additional layer for the extremely paranoid, but because pfsense already has encrypted configuration backup capabilities, I don't plan on spending much time on this any time soon.

      Fully agreed.

    • E

      How can I get OpenVPN to use QAT acceleration offload?

      OpenVPN
      • openvpn quickassist wireguard • • ensnare
      3
      1
      Votes
      3
      Posts
      664
      Views

      E

      @johnnyfive Yeah this is the problem - what a shame. It would be really great to have full acceleration using QuickAssist!

    • B

      WireGuard release 1.0.0

      General pfSense Questions
      • vpn wireguard • • bbusa
      6
      0
      Votes
      6
      Posts
      516
      Views

      J

      @jimp Yes would love this feature as wel. Tested it and works really fast en easy to setup. Timeline even for beta release would be great.
      OpenVpn has so much overhead, and just does not meet the speed requirements with low(er) end hardware.

    • I

      pfBlockerNG und Mullvad (Wireguard)

      Deutsch
      • wireguard • • iqjet
      1
      0
      Votes
      1
      Posts
      268
      Views

      No one has replied