• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DNS Resolution of server failing... but I can ping the box?

Scheduled Pinned Locked Moved WireGuard
dns resolutionfirewall ruleswireguard
5 Posts 2 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    lukeclover21
    last edited by Aug 29, 2022, 1:17 PM

    Hello,

    I am attempting to connect to my firewall with a wireguard tunnel and have it put the devices in a VLAN of their own with only access to that network. The address space I've chosen for that is 172.16.0.0/12.

    I have allowed ICMP echo reply requests to hit the firewall, and can ping it via my no-ip domain name no problem. However, when I attempt to connect to the firewall via wireguard, I get the following message.

    Screen Shot 2022-08-28 at 10.32.54 AM.png

    As far as I can tell, my configurations are correct. I'll include screenshots of my firewall rules as they are.

    Screen Shot 2022-08-29 at 8.02.48 AM.png

    Screen Shot 2022-08-29 at 8.03.22 AM.png

    wireguard-server-config-censored.png

    wireguard-client-config-censored.png

    Any suggestions are welcome. I'm pretty stumped. I can ping the wireguard server on both the lan and wan interfaces using the domain name from my intended client, but no dice on actually resolving the server via the wireguard software for some reason.

    S 1 Reply Last reply Aug 29, 2022, 3:12 PM Reply Quote 0
    • S
      SteveITS Galactic Empire @lukeclover21
      last edited by Aug 29, 2022, 3:12 PM

      @lukeclover21 The client is using the WireGuard interface as its DNS? I think you need a rule on that to allow port 53 TCP+UDP to This Firewall, or at least the WireGuard IP. (saying this having never used WireGuard)

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      L 1 Reply Last reply Aug 29, 2022, 7:10 PM Reply Quote 0
      • L
        lukeclover21 @SteveITS
        last edited by Aug 29, 2022, 7:10 PM

        @steveits No, the client should be using 1.1.1.1, then 8.8.8.8 as it's dns servers. Ideally I'd like to host my own dns, but right now I'm focused on getting this wireguard thing working first. I attempted to open that port externally but got the same result as before, cannot resolve the domain.

        S 1 Reply Last reply Aug 29, 2022, 7:20 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @lukeclover21
          last edited by Aug 29, 2022, 7:20 PM

          @lukeclover21 So if you're connecting out to the Internet then you should need a rule allowing devices on WireGuard to get out to those two IPs. And optionally the Internet. Interfaces are "deny by default."

          https://docs.netgate.com/pfsense/en/latest/recipes/wireguard-ra.html#firewall-rules
          "Next, add a rule to pass traffic inside the WireGuard tunnel"

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          L 1 Reply Last reply Aug 30, 2022, 2:29 AM Reply Quote 1
          • L
            lukeclover21 @SteveITS
            last edited by Aug 30, 2022, 2:29 AM

            So, after some further digging, I discovered a couple things.

            1. You have to actually assign the tunnel to an interface
            2. The MacOS Wireguard app doesn't support .ddns.net domains

            Thank you for your help, once I assigned the interface correctly everything worked like a charm.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received