• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

WireGuard multiple client bug

Scheduled Pinned Locked Moved pfSense Packages
wireguard
20 Posts 6 Posters 3.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bbusa
    last edited by Nov 4, 2021, 7:19 PM

    Has anyone created a WireGuard server on pfsense and tried to have more than one clients with it?
    I can only make one client working at the time, as soon as I add a new one, the old one stops working. Sounds like a bug, but just curious if anyone else encountered it.

    Handshake still goes through just no data in/out.
    While the other device other account with the same firewall settings, just different client pub/private key config works just fine.

    M P 2 Replies Last reply Nov 4, 2021, 9:45 PM Reply Quote 0
    • M
      MoonKnight @bbusa
      last edited by Nov 4, 2021, 9:45 PM

      @bbusa
      Hi, make sure you assign with different IP's on each client

      --- 24.11 ---
      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
      Kingston DDR4 2666MHz 16GB ECC
      2 x HyperX Fury SSD 120GB (ZFS-mirror)
      2 x Intel i210 (ports)
      4 x Intel i350 (ports)

      1 Reply Last reply Reply Quote 0
      • P
        psp @bbusa
        last edited by Nov 4, 2021, 10:19 PM

        @bbusa
        Hi, using 7 peers here all performing fine, even all together:

        2021-11-04_231722.png

        M B 2 Replies Last reply Nov 5, 2021, 6:14 AM Reply Quote 0
        • M
          MoonKnight @psp
          last edited by Nov 5, 2021, 6:14 AM

          @psp

          Almost the same:
          531851fb-7745-405e-a434-3b98beff9f34-image.png

          --- 24.11 ---
          Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
          Kingston DDR4 2666MHz 16GB ECC
          2 x HyperX Fury SSD 120GB (ZFS-mirror)
          2 x Intel i210 (ports)
          4 x Intel i350 (ports)

          1 Reply Last reply Reply Quote 0
          • B
            bbusa
            last edited by Nov 5, 2021, 7:14 AM

            I have set allowed IPs 0.0.0.0/0 for both clients and manually set the clients IP in their configs.

            Do I manually have to specify the allowed IPs in the client config in pfsense?

            M 1 Reply Last reply Nov 5, 2021, 9:03 AM Reply Quote 0
            • M
              MoonKnight @bbusa
              last edited by Nov 5, 2021, 9:03 AM

              @bbusa

              I have manually set the IP on the clients.

              9ef0d895-266d-426f-abae-bd64bfaeb4ee-image.png

              --- 24.11 ---
              Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
              Kingston DDR4 2666MHz 16GB ECC
              2 x HyperX Fury SSD 120GB (ZFS-mirror)
              2 x Intel i210 (ports)
              4 x Intel i350 (ports)

              B 1 Reply Last reply Nov 5, 2021, 9:09 AM Reply Quote 0
              • B
                bbusa @MoonKnight
                last edited by Nov 5, 2021, 9:09 AM

                @ciscox What do you set on the client side? I want to tunnel all traffic via the pfsense when connected.

                What do you set for allowed IPs on the client device?

                M 1 Reply Last reply Nov 5, 2021, 3:29 PM Reply Quote 0
                • M
                  MoonKnight @bbusa
                  last edited by Nov 5, 2021, 3:29 PM

                  @bbusa

                  This is my client-side settings:

                  2efcd8e8-7dc3-46c1-833c-1a2505a3cc6f-image.png

                  --- 24.11 ---
                  Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                  Kingston DDR4 2666MHz 16GB ECC
                  2 x HyperX Fury SSD 120GB (ZFS-mirror)
                  2 x Intel i210 (ports)
                  4 x Intel i350 (ports)

                  B 1 Reply Last reply Nov 5, 2021, 5:17 PM Reply Quote 0
                  • B
                    boessi @MoonKnight
                    last edited by Nov 5, 2021, 5:17 PM

                    Have the same issue when setting up multiple peers, only the last one added is working. Was thinking it was a iOS15 Bug as the Peer was not able to connect arount the time iOS15 came out, but after deleting the Peer and recreating it it now works but the other peer is no longer working. Sounds like the same issue.

                    @bbusa is only the last created one working on your side as well?

                    f22e88f4-aaa9-45b8-b495-e14aa747245f-image.png

                    M B A 3 Replies Last reply Nov 5, 2021, 5:36 PM Reply Quote 1
                    • M
                      MoonKnight @boessi
                      last edited by MoonKnight Nov 5, 2021, 5:40 PM Nov 5, 2021, 5:36 PM

                      @boessi
                      Hi, I see you have the same endpoint port on your clients, mine is different for every new device that is connected

                      a2f74019-a23b-4103-8f3a-373f399b1669-image.png

                      --- 24.11 ---
                      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                      Kingston DDR4 2666MHz 16GB ECC
                      2 x HyperX Fury SSD 120GB (ZFS-mirror)
                      2 x Intel i210 (ports)
                      4 x Intel i350 (ports)

                      B 1 Reply Last reply Nov 6, 2021, 7:34 AM Reply Quote 0
                      • B
                        bbusa @MoonKnight
                        last edited by Nov 6, 2021, 7:34 AM

                        @ciscox using different endpoints are basically creating different servers for different clients.

                        My whole point was that one server should be able to communicate with multiple clients at the same time using the same receiving port.

                        1 Reply Last reply Reply Quote 0
                        • B
                          bbusa @boessi
                          last edited by Nov 6, 2021, 7:38 AM

                          @boessi yes that’s exactly the “bug” I have encountered too.

                          1 Reply Last reply Reply Quote 0
                          • B
                            bbusa @psp
                            last edited by Nov 6, 2021, 7:41 AM

                            @psp do you have them all working at the same time too?

                            P 1 Reply Last reply Nov 6, 2021, 1:16 PM Reply Quote 0
                            • P
                              psp @bbusa
                              last edited by Nov 6, 2021, 1:16 PM

                              @bbusa
                              Yes, but I need (according to my config) to identify any road warrior device with its own IP in order to define different rules and to route VPN traffic only for defined subnets (i.e. no 0.0.0.0/0).

                              1 Reply Last reply Reply Quote 0
                              • A
                                ahking19 @boessi
                                last edited by Nov 6, 2021, 7:53 PM

                                @boessi the peer endpoint should be your WAN IP not private IP space like you are using - 10.0.0.x.

                                It is not the same address space as your tunnel address/assignment.

                                B 1 Reply Last reply Nov 6, 2021, 8:25 PM Reply Quote 0
                                • B
                                  boessi @ahking19
                                  last edited by Nov 6, 2021, 8:25 PM

                                  @ahking19 the configuration is working from inside and outside the network, the configuration on the phone is using the wan ip as normal. the internal ip's are the internal peer ip's and thats like in all the guids I can find. The problem is only that just one of the config is working (the newest) as soon as I delete the newest one the one that is currently not working is working again. everything up until the handshake is woriking but then nothing happens. maybe good to point out, I had a working peer for a longer time, then I added a second peer that worked too, but since then my previous peer was not working anymore up to the point where I delete the newer peer and the old config started to work again.

                                  Client Config (not working after creating the iPhone Peer that is working)

                                  [Interface]
                                  PrivateKey = aM7J.......
                                  ListenPort = 51820
                                  Address = 10.0.0.20/24
                                  DNS = 10.0.0.1
                                  
                                  [Peer]
                                  PublicKey = fRz1.....
                                  AllowedIPs = 0.0.0.0/0, ::/0
                                  Endpoint = wan.dns.tld:51820
                                  
                                  

                                  So the address is in the range of ther internal interface. The exact same configuration for the other peer is working (up until creating a new peer configuration).

                                  The configuration is nothing special and as said, one peer is always working, but just the newest created peer.

                                  B 1 Reply Last reply Nov 6, 2021, 8:41 PM Reply Quote 0
                                  • B
                                    boessi @boessi
                                    last edited by Nov 6, 2021, 8:41 PM

                                    Server Config

                                    [Interface]
                                    PrivateKey = KGqqu.....
                                    ListenPort = 51820
                                    
                                    # Peer: Windows
                                    [Peer]
                                    PublicKey = uiYic...
                                    AllowedIPs = 0.0.0.0/0
                                    
                                    # Peer: iPhone
                                    [Peer]
                                    PublicKey = ZWTd...
                                    AllowedIPs = 0.0.0.0/0
                                    
                                    1 Reply Last reply Reply Quote 1
                                    • J
                                      jimp Rebel Alliance Developer Netgate
                                      last edited by Nov 9, 2021, 2:55 PM

                                      On the "server" you do not put 0.0.0.0/0 into allowed IPs. That doesn't tell the server which networks that the client can reach. It tells the server which address belongs to the client.

                                      For the client to reach anything you put the 0.0.0.0/0 in the client's allowed IPs list. On the server you put the IP address assigned to that client.

                                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                      Need help fast? Netgate Global Support!

                                      Do not Chat/PM for help!

                                      B 1 Reply Last reply Nov 9, 2021, 3:34 PM Reply Quote 1
                                      • B
                                        boessi @jimp
                                        last edited by boessi Nov 9, 2021, 3:42 PM Nov 9, 2021, 3:34 PM

                                        @jimp ok, so the server config is a extract from the file system, I only use the package interface and as every guide mentioned to put 0.0.0.0/0 into the peer config I just do that :) . Will try to put the client ip (10.0.0.20/32) into it and will try again.

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          boessi
                                          last edited by Nov 9, 2021, 6:48 PM

                                          @jimp thx for the hint it's working now, it totally make sense now. hope it will you @bbusa as well

                                          1 Reply Last reply Reply Quote 0
                                          20 out of 20
                                          • First post
                                            20/20
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received