Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WireGuard, Two Firewall Entries

    WireGuard
    3
    6
    807
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • arrmoA
      arrmo
      last edited by

      Hi,

      Likely a dumb question, but just not fitting with my brain (yet) 🤣 . In my Firewall Rules, I see two WireGuard entries ... seems like one is interface, the other the "application" (for lack of a better term). Should there be? And what is the difference / which one is needed?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • G
        Griffo
        last edited by

        @arrmo It's explained in the doco.
        https://docs.netgate.com/pfsense/en/latest/vpn/wireguard/rules.html

        The Group rules are processed first, then the interface rules. Just like floating rules and interface rules on the firewall.

        So I think for inbound traffic the order will be Floating -> Wireguard -> wgx but outbound is a little more complicated.

        arrmoA 2 Replies Last reply Reply Quote 1
        • arrmoA
          arrmo @Griffo
          last edited by

          @griffo That makes sense, thanks! So if I pass at the Group level, no need for a rule "below" that (i.e. interface).

          Appreciate it!

          1 Reply Last reply Reply Quote 0
          • arrmoA
            arrmo @Griffo
            last edited by

            @griffo said in WireGuard, Two Firewall Entries:

            The Group rules are processed first, then the interface rules. Just like floating rules and interface rules on the firewall.

            Just to clarify (make sure I have it correct 🤣). It seems like the rules are processed Left to Right, as they show up in the webConfigurator. Correct?

            Thanks!

            cmcdonaldC 1 Reply Last reply Reply Quote 0
            • cmcdonaldC
              cmcdonald Netgate Developer @arrmo
              last edited by

              @arrmo The order is somewhat arbitrary, fwiw you can change the ordering to alphabetical if you want in General Setup settings.

              Thttps://docs.netgate.com/pfsense/en/latest/nat/process-order.html

              Need help fast? https://www.netgate.com/support

              arrmoA 1 Reply Last reply Reply Quote 1
              • arrmoA
                arrmo @cmcdonald
                last edited by

                @vbman213 That link helps, appreciate it!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.