• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

wireguard config - can connect but cannot ping LAN hosts from phone

Scheduled Pinned Locked Moved WireGuard
5 Posts 2 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mushinsky
    last edited by Sep 3, 2023, 3:13 PM

    I was able to connect my phone but it cannot see hosts inside LAN.

    LAN has addresses 192.168.1.0/24, router is 192.168.1.1
    Tunnel address is 192.168.2.0
    WAN uses Dynamic DNS

    Symptoms:

    • Handshake is completed, phone connects
    • I can ping 192.168.2.0 from hosts on LAN. But not my router or anything from the phone.

    Q1. What to do?
    Q2. Also, if I change the interface address to 192.168.2.0/24, on the pfsense side it complains that it is a "network address and cannot be used". It is fine with one client, but what if I have more in future? Why is there the mask field at all in the configuration then?

    Here is my config (only keys edited away)

    On the server (which is a pfsense router)

    Description: external

    [Interface]
    PrivateKey = [...]
    ListenPort = 51820

    Peer: pixel7

    [Peer]
    PublicKey = [Z46...]
    AllowedIPs = 192.168.2.0/24
    PersistentKeepalive = 0

    On the phone

    [Interface]
    Name=tun
    PublicKey= [Z46...]
    Addresses=192.168.2.0/32, 192.168.1.0/24
    DNS servers 8.8.8.8 (for now, I would really like 192.168.1.1 later to get names within LAN)
    ListenPort=51820

    #Peer
    PublicKey=[...]
    AllowedIPs=192.168.1.0/24,192.168.2.0/24
    Endpoint=gateway.xxx.com:51820

    Firewall

    • WAN allows everything on IPv4/IPv6 UDP on port 51820
    • WireGuard group contains wg tunnel interface and allows everything. For good measure, the wg interface also has a (likely useless) rule to allow anything.
    • Outbound below

    3fcf996e-590f-4a54-bbad-ba4d96b2cbd5-image.png

    Any ideas?

    B 1 Reply Last reply Sep 3, 2023, 4:11 PM Reply Quote 0
    • B
      Bob.Dig LAYER 8 @mushinsky
      last edited by Sep 3, 2023, 4:11 PM

      @mushinsky said in wireguard config - can connect but cannot ping LAN hosts from phone:

      but it cannot see hosts inside LAN.

      What hosts?

      M 1 Reply Last reply Sep 3, 2023, 5:31 PM Reply Quote 0
      • M
        mushinsky @Bob.Dig
        last edited by Sep 3, 2023, 5:31 PM

        @Bob-Dig e.g. 192.168.1.3 (NAS)
        Or the router itself, 192.168.1.1

        1 Reply Last reply Reply Quote 0
        • M
          mushinsky
          last edited by Sep 5, 2023, 6:48 PM

          Still no luck with this. Any suggestions?

          B 1 Reply Last reply Sep 6, 2023, 6:32 AM Reply Quote 0
          • B
            Bob.Dig LAYER 8 @mushinsky
            last edited by Bob.Dig Sep 6, 2023, 6:43 AM Sep 6, 2023, 6:32 AM

            @mushinsky You can't have two addresses for the interface and you also have other problems. Maybe take a closer look here.

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received