• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Wireguard is not routing any traffic

WireGuard
6
44
10.6k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    matosc
    last edited by Aug 26, 2022, 6:55 PM

    My surfshark wireguard configuration is not working. I'm sure it must be something incredibly obvious, but I can't figure it out.

    Can someone please scan the config below and let know what is missing. For testing I have it configured like @Thisisme 's example.

    fyi .... I am using selective routing and have a couple of LAN devices that are configured with firewall rules to only route to the surfshark wireguard gateway. Also, my OpenVPN config is fine.

    login-to-view

    login-to-view

    login-to-view

    login-to-view

    login-to-view

    login-to-view

    login-to-view

    login-to-view

    B 1 Reply Last reply Aug 26, 2022, 8:29 PM Reply Quote 0
    • B
      Bob.Dig LAYER 8 @matosc
      last edited by Bob.Dig Aug 26, 2022, 8:35 PM Aug 26, 2022, 8:29 PM

      @matosc Do you have two Gateways for that connection?

      Today I noticed that pfSense isn't really doing any cleaning with gateways when I removed all OVPN connections and later removed all WG connections...
      OVPN runs great with ss. I think it is even using DCO but I am not sure.

      M 1 Reply Last reply Aug 27, 2022, 11:15 AM Reply Quote 0
      • M
        matosc @Bob.Dig
        last edited by Aug 27, 2022, 11:15 AM

        @bob-dig I have several gateways, with only 1 for the wireguard connection.

        1. WAN
        2. Surfshark Wireguard
        3. Surfshark OpenVPN - near my location
        4. Surfshark OpenVPN - for USA connections

        login-to-view

        Helps?

        B 1 Reply Last reply Aug 27, 2022, 11:47 AM Reply Quote 0
        • B
          Bob.Dig LAYER 8 @matosc
          last edited by Aug 27, 2022, 11:47 AM

          @matosc Maybe you can't have two connections simultaneously (OVPN and WG) to the same server? I am back on OVPN so I can't help anymore.

          M 1 Reply Last reply Aug 27, 2022, 12:30 PM Reply Quote 0
          • M
            matosc @Bob.Dig
            last edited by Aug 27, 2022, 12:30 PM

            @bob-dig I really appreciate the help.

            I changed my config to test this more - recreated the wireguard configuration and removed the OpenVPN connections entirely.

            Still can't connect from the single device on the network that is configured with a LAN rule to only connect to the specified gateway.

            login-to-view

            Here is the latest config.

            login-to-view

            login-to-view

            login-to-view

            login-to-view

            login-to-view

            login-to-view

            login-to-view

            login-to-view

            B 1 Reply Last reply Aug 27, 2022, 12:40 PM Reply Quote 0
            • B
              Bob.Dig LAYER 8 @matosc
              last edited by Bob.Dig Aug 27, 2022, 12:46 PM Aug 27, 2022, 12:40 PM

              @matosc You could switch to Automatic Outbound NAT for now if you don't use OVPN.
              Have you given your public Key to ss in their WebUI?
              Your LAN rule has no fault?
              No rules on the WireGuard Group Interface, if it exist.

              I just got WG from pfSense to my android phone working, it took me ages... 🤢

              M 1 Reply Last reply Aug 27, 2022, 4:36 PM Reply Quote 0
              • M
                matosc @Bob.Dig
                last edited by Aug 27, 2022, 4:36 PM

                @bob-dig thanks for idea of turning on Automatic Outbound NAT. It's working! There must have been a hidden issue in the background. Anyway, I'm very happy that I can finally connect via WG.

                Everyone once and a while I lose WG connection and route via the WAN. This kinda sounds like what others are experiencing. Will track this topic and see if others report the same.

                1 Reply Last reply Reply Quote 0
                • B
                  Bob.Dig LAYER 8
                  last edited by Bob.Dig Sep 7, 2022, 1:56 PM Sep 7, 2022, 1:56 PM

                  @Thisisme How is it going? How many WG-tunnels have you running with ss?

                  ? 1 Reply Last reply Sep 7, 2022, 2:05 PM Reply Quote 0
                  • ?
                    A Former User @Bob.Dig
                    last edited by Sep 7, 2022, 2:05 PM

                    @bob-dig I have one tunnel atm. But I'm not sure about it. I have the same problem with OpenVPN and WG: several times a day I get packet loss leading to gateway shutdown. But with WG it seems more often.

                    B J 2 Replies Last reply Sep 7, 2022, 2:08 PM Reply Quote 0
                    • B
                      Bob.Dig LAYER 8 @A Former User
                      last edited by Bob.Dig Sep 7, 2022, 2:10 PM Sep 7, 2022, 2:08 PM

                      @thisisme I went crazy today and created 5 VMs, each with OpenWRT. Every VM has one WG-tunnel and all are connected to pfSense. I use these as gateways, so no more overlapping IP issues. Lets see how it goes. 😉

                      1 Reply Last reply Reply Quote 0
                      • J
                        Jarhead @A Former User
                        last edited by Sep 7, 2022, 3:38 PM

                        @thisisme said in Wireguard is not routing any traffic:

                        @bob-dig I have one tunnel atm. But I'm not sure about it. I have the same problem with OpenVPN and WG: several times a day I get packet loss leading to gateway shutdown. But with WG it seems more often.

                        Set your Wireguard interface MTU to 1420.

                        B 1 Reply Last reply Sep 7, 2022, 3:54 PM Reply Quote 0
                        • B
                          Bob.Dig LAYER 8 @Jarhead
                          last edited by Bob.Dig Sep 7, 2022, 3:55 PM Sep 7, 2022, 3:54 PM

                          @Thisisme With my 5 virtual OpenWRT Routers I have no problems at all, running fantastic. So it might be that ss doesn't like the pfSense implementation of WG.

                          login-to-view

                          JeGrJ 1 Reply Last reply Sep 16, 2022, 2:12 PM Reply Quote 0
                          • JeGrJ
                            JeGr LAYER 8 Moderator @Bob.Dig
                            last edited by Sep 16, 2022, 2:12 PM

                            @bob-dig You're living on the edge with these dummy GW IPs (1.1.1.2-7). Those are NO valid IPs from CF DNS but random services that can be on- and off at will. I'd think about better not using those if I don't exactly know where or what is behind them ;)

                            Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                            B 1 Reply Last reply Sep 16, 2022, 2:53 PM Reply Quote 1
                            • B
                              Bob.Dig LAYER 8 @JeGr
                              last edited by Sep 16, 2022, 2:53 PM

                              @jegr Using them for years now without a problem but thanks for the heads up, it is only for my personal use anyway.

                              1 Reply Last reply Reply Quote 0
                              • B
                                Bob.Dig LAYER 8
                                last edited by Bob.Dig Sep 18, 2022, 2:13 PM Sep 18, 2022, 2:13 PM

                                @JeGr Apropos living on the edge. 😉

                                login-to-view

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.