<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[WG Sporadic, TCPDUMP question.]]></title><description><![CDATA[<p dir="auto"><strong>Preface</strong><br />
My Wireguard iOS peers will sometimes run for a few minutes (cell or remote wifi) before they stop receiving handshakes, sometimes for half a minute, sometimes for a few seconds, and then nothing. I think my setup is roadwarrior and I basically need WG to check out my camera NVR. But the same drops happen when I occasionally like to check out my pfSense router.</p>
<p dir="auto"><strong>Clues</strong><br />
The first iOS WG connections of the day always run great, but only for a few minutes.<br />
Each successful connection runtime thereafter gets progressively shorter and shorter.<br />
Then no handshake at all.<br />
Peer logs will say connected, but handshake responses are not received.</p>
<p dir="auto">Also, the first successful iOS connections will show data sent/received.<br />
Thereafter, only sent data is shown when I initiate WG.</p>
<p dir="auto">I would have to wait a few hours before I can get a complete handshake again.<br />
Then the same cycle repeats itself.</p>
<p dir="auto">The WG interface on "pfSence Interface Statistics" shows 0 Errors In and 443 Errors Out.</p>
<p dir="auto"><strong>Repair attempts</strong><br />
I've tried various suggested MTU/MSS settings (1428, 1280, 1450) on iOS and router interface but they have no affect.</p>
<p dir="auto">Restarting WG on pfSence has no effect.</p>
<p dir="auto">A lot of web searches were conducted and I found people with the same complaints but there are no solid solutions, so I would like to get a better understanding of pulling TCPDUMP logs from my WG interface. Then I can try to dig further and find more clues.</p>
<p dir="auto"><strong>The ask</strong><br />
I know how to do this via SSH but exactly what tcpdump syntax should I use?<br />
And <em>maybe</em> this is too general of a question, what anomalies should I look out for?</p>
<p dir="auto">Best,<br />
Chris</p>
<p dir="auto">pfSense 2.6.0<br />
Snort<br />
pfBlockerNG<br />
Avahi for IOT</p>
]]></description><link>https://forum.netgate.com/topic/166699/wg-sporadic-tcpdump-question</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 01:22:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/166699.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Sep 2021 22:16:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to WG Sporadic, TCPDUMP question. on Tue, 05 Oct 2021 18:25:11 GMT]]></title><description><![CDATA[<p dir="auto">I've hit a roadblock here. Is there somebody who can offer a bit of advice?</p>
]]></description><link>https://forum.netgate.com/post/1004529</link><guid isPermaLink="true">https://forum.netgate.com/post/1004529</guid><dc:creator><![CDATA[DIYsense]]></dc:creator><pubDate>Tue, 05 Oct 2021 18:25:11 GMT</pubDate></item></channel></rss>