Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. wireguard
    Log in to post

    • All categories
    • P

      Multiple Wireguard Tunnels - How to set Tier 1 and 2 for priorities to achieve Failover Behavior

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard vpn gatewaygroup
      3
      0 Votes
      3 Posts
      1k Views
      P
      @Bob.Dig I will work on some pics but it's been in a state of evolution as a test network running another scenario at the moment - but when I can switch it back to this I was looking for some things to focus on and try. I used an interface group for NAT rules because one of the tutorials I read showed to do that and said create a group or do rules for every one. Seemed like a group would be best practice then for larger numbers - but you you recommend to just do a NAT entry for each instead?
    • P

      Wireguard outbound is fine; inbound seemingly blocked?

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN routing wireguard firewall
      2
      4
      0 Votes
      2 Posts
      5k Views
      P
      Traceroute from the outside world: vpsuser@test:~$ sudo traceroute -I a.b.c.164 traceroute to a.b.c.164 (a.b.c.164), 30 hops max, 60 byte packets 1 daniel.domesticagriculture.org.uk (103.144.176.193) 0.518 ms 0.470 ms 0.457 ms 2 wist.lyle.org (103.144.176.143) 0.479 ms * * 3 100.64.101.167 (100.64.101.167) 10.793 ms 10.781 ms * 4 * * * 5 * * * 6 * * * 7 * * * ... 100.64.101.167 is my router's WG client IP
    • M

      Wireguard Site-to-site not passing traffic

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard site-to-site routing
      13
      0 Votes
      13 Posts
      2k Views
      patient0P
      @MartynK that's ok, it's a bit odd that a reboot was necessary. Maybe it was the MTU changes?
    • D

      Weird issue with certain traffic "dissapearing" when going in wireguard tunnel

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard vpn nat rules portforward
      4
      3
      0 Votes
      4 Posts
      2k Views
      S
      My eyes are having a hard time getting beyond 250.0.0.0. Just something about it. I say this as a free thinker that regularly uses 172.20.20.0 or 172.21.21.0 I'm putting my money on a DNS entry feeding a public IP address instead of an internal IP address, and therefore not trying to send the 25 out the tunnel, and then the ISP knocking down the port 25 traffic.
    • M

      Site-to-Site Wireguard: Very high CPU usages

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions wireguard cpu stats vpn tunnel
      15
      2
      0 Votes
      15 Posts
      2k Views
      stephenw10S
      The CPU in the 8200 is a lot more powerful so you see the widget usage in the 1100 far more. That is especially so because the refresh rate can start to hit the time taken to pull the data. Did you try the patch linked above to revert to the previous widget behaviour?
    • A

      Firewall Rules for Wireguard S2S VPN in a Multi-WAN Environment with Multiple LAN

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard s2s vpn wireguard
      4
      0 Votes
      4 Posts
      837 Views
      A
      @Bob-Dig EDIT: Changing the default gateway under the "Routing" tab again caused the remote site to be inaccessible via the S2S VPN.
    • A

      Route-Based IPSec vs Wireguard Tunnel Subnet Choice for S2S VPN

      Watching Ignoring Scheduled Pinned Locked Moved IPsec s2s ipsec wireguard vpn
      5
      0 Votes
      5 Posts
      828 Views
      A
      @Gblenn Just tested it with /31 and it works. For route-based IPsec the gateway is created automatically when you assign the tunnel to an interface. I haven't tried with /32 tho. But I tried with larger subnet like /24. I guess it's like what you said, as long as they are on the same subnet it will work. Just that for point-to-point connection with a single transit network it doesn't make sense to use something larger that contains more than 2 IPs.
    • P

      Novice trying to diagnose internet problems when using Wireguard with ProtonVPN

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard vpn protonvpn pfsense 23.09 sg-1100
      1
      0 Votes
      1 Posts
      422 Views
      No one has replied
    • T

      Wireguard and Bonjour/Avahi

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard avahi vpn wireguard
      4
      0 Votes
      4 Posts
      1k Views
      T
      @dennypage Okay thanks.
    • H

      Can't perform WireGuard handshake when connected to WAN using PPoE?

      Watching Ignoring Scheduled Pinned Locked Moved NAT firewall wan wireguard rules pppoe
      5
      0 Votes
      5 Posts
      1k Views
      H
      @Bob-Dig thanks for your feedback again! Yeah, I think they are assigned properly, unless I'm missing something here and PPPoE actually requires a different assignment. [image: 1719260898527-assigments.png] [image: 1719260903240-gateways.png] Thank you!
    • R

      Pfsense Software, WireGuard VPN

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions pfsense vpn wireguard simple self hosted
      2
      0 Votes
      2 Posts
      601 Views
      G
      @Ratfink Connecting two sites with Wireguard VPN is absolutely doable, and you don't even need fixed IP's for it to work. When you say you have 5 fixed IP's from your ISP, I'm kind of assuming you have your office at your house? Meaning they are both connected to the same fibre? Otherwise, if they are at very different locations, is it still the same ISP? In terms of getting the IP's on the respective pfsense machines, I assume you know how or have instructions from the ISP to do this. Might be MAC based if DHCP for example... Anyway, running pfsense on repurposed HW is very common and can be done "barebone" or virtualized. So you shouldn't have any problems getting to to work on your rack servers, hopefully. So step one is of course getting both machines up and running. And since they will be for different sites and connected via VPN you must make sure to use different LAN subnets on them. Like 192.168.1.0/24 on one and 192.168.2.0/24 on the other. Once you have them up and running you can follow a guide like one of these to set up wireguard. Even though you have fixed IP's it might be a good idea to get two domains, unless you already have that. https://www.youtube.com/watch?v=2oe7rTMFmqc https://www.youtube.com/watch?v=7_gLPyipFkk
    • T

      Wireguard gateway no working outside dashboard

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard static route vpn tunnel site-to-site site to site
      13
      6
      0 Votes
      13 Posts
      3k Views
      T
      Finally! The solution was creating a firewall rule that route the traffic of my Bridge interface through the gateway i have created for the wireguard client.
    • N

      Wireguard pfSense -> Speedport: Kein Verbindungsaufbau

      Watching Ignoring Scheduled Pinned Locked Moved Deutsch wireguard pfsense speedport vpn
      1
      0 Votes
      1 Posts
      841 Views
      No one has replied
    • JustAnotherUserJ

      Port Forward over VPN not working....

      Watching Ignoring Scheduled Pinned Locked Moved NAT port forward wireguard vpn
      5
      2
      0 Votes
      5 Posts
      1k Views
      V
      @JustAnotherUser said in Port Forward over VPN not working....: If you want to go over WAN anyway, assign an interface to the wg instance and enable it at site 2. This brings up a new firewall rule tab for it then. Now go to the "Wireguard" tab, edit the existing rules and change the interface to the new one. I'm not sure what you mean by your last sentence but, I've done the rest. You mean, changing the interface in the filter rule? In Firewall > Rules you will see a tab called "Wireguard". pfSense might have created a rule on this tab automatically, when you set up the Wireguard tunnel. So go to this tab and edit the existing rule and change the interface from "Wireguard" to the interface, which you have assigned to the Wireguard instance before. Then the rule disappears from the Wireguard tab and appear on the new interface tab. Also in the WG settings on router 2 you have to change the "allowed IPs" to 0.0.0.0/0 to accept public forwarded traffic.
    • F

      Wireguard + Port Forwarding = Return Traffic exiting through WAN???

      Watching Ignoring Scheduled Pinned Locked Moved NAT portforward wireguard vpn
      4
      5
      0 Votes
      4 Posts
      2k Views
      D
      @FoolCoconut said in Wireguard + Port Forwarding = Return Traffic exiting through WAN???: Holy f**k. The problem was an any/any rule in the Wireguard unasigned tunnel firewall rule list. Even though the AirVPN WG interface was assigned, group rules are evaluated first... Hope this helps someone else as well. @FoolCoconut THANK you. ive been trying to figure this out for a very long time.
    • H

      Can't get Wireguard to work

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard
      4
      0 Votes
      4 Posts
      921 Views
      H
      @hspindel Update, finally got the VPN tunnel to work!
    • S

      Cannot establish socks5 connection via dante

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN socks5 pfsense socks5 dante wireguard
      3
      0 Votes
      3 Posts
      2k Views
      S
      Couldn't get dante to work until I found this. For those of you sportsfans keeping score at home, this is still valid/needed for pfSense version 2.7.2-CE and dante-1.4.3_2 circa 2/2025.
    • S

      How do I route outgoing email over WireGuard Tunnel?

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN wireguard tunnels routiing help gateway
      29
      0 Votes
      29 Posts
      6k Views
      Bob.DigB
      @Gertjan said in How do I route outgoing email over WireGuard Tunnel?: Of course I use have DANE available and set up : I just noticed I had to recreate the TLSA records, something with Let's Encrypt must have changed. I hope I am good now for some time...
    • K

      Wireguard vpn - remote device can't do local DNS resolution

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions wireguard vpn dns
      8
      0 Votes
      8 Posts
      7k Views
      stephenw10S
      Yup, those devices are probably not trying to resolve .local addresses using DNS servers at all. They assume they are mDNS and try to find them locally.
    • H

      Wireguard and 23.01

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard wireguard releases
      5
      0 Votes
      5 Posts
      1k Views
      H
      @jimp Thank you! Sorry I didn't run across this in my reviews of other forums. That was EXACTLY what I was looking for!