• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Wireguard Firewall Rules

Scheduled Pinned Locked Moved WireGuard
4 Posts 2 Posters 632 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Thondwe
    last edited by Feb 13, 2023, 4:32 PM

    Have got Wireguard setup - pfsense to iphone at the second attempt. But somewhat puzzled - on Tom's tutorial the firewall rules page just has "wireguard" as an interface for rules, but mine (latest release of pfsense dev and wireguard) has an additional interface for my tunnel. The rules to allow traffic (full tunnel) only work on "wireguard".

    Can someone point me to the explaination please? - I'm guessing "work in progress" and rules will eventually go on each tunnel???

    Thanks

    J 1 Reply Last reply Feb 13, 2023, 4:41 PM Reply Quote 0
    • J
      Jarhead @Thondwe
      last edited by Jarhead Feb 13, 2023, 4:42 PM Feb 13, 2023, 4:41 PM

      @thondwe It depends on if you assigned an interface (ie OPTx) to the tunnel or just assigned the IP in the Wireguard config itself.
      I can't see any real reason to assign an interface to a remote access tunnel but some people seem to do that.

      If interface assigned, use the interface for rules.
      If no interface assigned, use the Wireguard group for rules.

      This also depends on this setting:
      wg.png

      T 1 Reply Last reply Feb 14, 2023, 9:43 AM Reply Quote 0
      • T
        Thondwe @Jarhead
        last edited by Feb 14, 2023, 9:43 AM

        @jarhead Thanks got it now - read through a couple of tutorials, one of which must have including assigning the interface. I assume if I change that setting from "all", I can get the interface rules to kick in.

        Assume the benefit of assigning would come into play with multiple tunnels with a need for different rules then? e.g. Test + Production? Or when using a site-to-site setup??

        J 1 Reply Last reply Feb 14, 2023, 11:31 AM Reply Quote 0
        • J
          Jarhead @Thondwe
          last edited by Feb 14, 2023, 11:31 AM

          @thondwe said in Wireguard Firewall Rules:

          Assume the benefit of assigning would come into play with multiple tunnels with a need for different rules then? e.g. Test + Production? Or when using a site-to-site setup??

          Exactly. And how often do you have multiple remote access tunnels on the same system? Usually one would just make one RA tunnel with a big enough subnet for however many users they would need. So no real need for an interface.
          But site to sites definitely benefit from the separate rules.

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received