• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Wireguard gateway no working outside dashboard

Scheduled Pinned Locked Moved WireGuard
wireguardstatic routevpn tunnelsite-to-sitesite to site
13 Posts 3 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    technoblue
    last edited by technoblue Feb 3, 2024, 11:07 AM Feb 3, 2024, 10:56 AM

    I have configured wireguard and stablish the connection with my other site, if i test it with the ping tool in the dashboard it works

    cd9b6302-ef95-4f33-aea4-85c69f709657-imagen.png

    But when I try to ping or connect from my pc or other network device it doesn´t connect

    fc9f4177-54b4-445e-a6b8-79e4a34b6325-imagen.png

    Also I have a bridge config in my 3 LAN ports to act as a switch and if I select that bridge as source address it doesn´t work either

    116f43fa-4658-4c09-9974-847d931a5a7f-imagen.png
    a4bb6740-e35c-4cb6-9c5a-99ec3a3dc804-imagen.png

    local network: 10.2.0/24
    WG network: 10.95.99.0/24
    other site network 192.168.15.0/24

    Static Route config:
    e533d622-75e9-4bf7-835a-7ed2574acd80-imagen.png

    Firewall config:
    0bcb5f9d-5625-47f2-9031-469decb5db89-imagen.png

    Someone have some clue?

    1 Reply Last reply Reply Quote 0
    • P
      PlyrStar93
      last edited by PlyrStar93 Feb 5, 2024, 7:34 AM Feb 5, 2024, 7:30 AM

      In your 10.2.0.0/24 Windows PC, perform a trace route to 192.168.15.210 and see which route it goes. It's possible that the devices in your local LAN are not following the static route defined (possibly due to firewall rules on the bridge interface forcing the traffic through a particular gateway).

      Also, can you show the allowed IPs configured for the peers on both sides just in case? In addition, the firewall rules of MYSWITCH interface, and the general configs of LAN and MYSWITCH interfaces (include the IPv4 settings).

      T 1 Reply Last reply Feb 5, 2024, 10:32 AM Reply Quote 0
      • T
        technoblue @PlyrStar93
        last edited by Feb 5, 2024, 10:32 AM

        @PlyrStar93

        The tracert comand fail as the gateway doesn`t route it

        I only have the config of the peer of pfsense as the other device is a qnap router and in that side i can´t see the peer config, but i think that if in the pfsense dashboard the ping works it have to be something in the gateway config or static routes...

        Pfsense peer config:

        f9f4cc76-86bf-4419-acda-90a391222532-image.png

        Firewall rules MYSWITCH

        00ab347b-388c-4925-bf2f-8773cae83986-image.png

        LAN Config:

        721ffc6d-d18f-4d49-a76d-559781f4d89f-image.png

        MYSWITCH Config:

        e1b02464-9079-45c8-ac98-5a5d58a6a2a9-image.png

        1 Reply Last reply Reply Quote 0
        • T
          technoblue
          last edited by technoblue Feb 8, 2024, 10:42 PM Feb 8, 2024, 10:38 PM

          Traceroute working
          92c24e83-224f-4eee-82ef-525c6a6a58a6-imagen.png

          But when I select the interface MYSWITCH (this is what i use as i use my 3 LAN ports)

          aa1abfe8-a294-43ce-892a-c9922517f5fd-imagen.png

          T 1 Reply Last reply Feb 14, 2024, 4:53 PM Reply Quote 0
          • T
            technoblue @technoblue
            last edited by Feb 14, 2024, 4:53 PM

            Someone know what cloud be happening?

            J 1 Reply Last reply Feb 14, 2024, 5:24 PM Reply Quote 0
            • J
              Jarhead @technoblue
              last edited by Feb 14, 2024, 5:24 PM

              @technoblue Judging by your Firewall Rules I'd assume you're not using an interface for the tunnel so what rules do you have on the Wireguard tab?

              T 1 Reply Last reply Feb 14, 2024, 6:08 PM Reply Quote 0
              • T
                technoblue @Jarhead
                last edited by Feb 14, 2024, 6:08 PM

                @Jarhead

                Hi! Yes I´m using an interface

                a2577576-5d81-44c4-af00-a358137147d7-imagen.png

                What I don´t understand is why the ping works with the LAN interface, but it doesn´t works with the "MYSWITCH" interface, this one I use to have 3 LAN ports of my box

                e325ec81-f7db-45f0-aadf-224202e03653-imagen.png
                4d256022-9771-4b1e-b1ba-7ddf4d60c8a6-imagen.png

                J 1 Reply Last reply Feb 14, 2024, 6:50 PM Reply Quote 0
                • J
                  Jarhead @technoblue
                  last edited by Feb 14, 2024, 6:50 PM

                  @technoblue You need to set the MTU to 1420 on the WG interface.
                  Do a constant ping from the far end while doing a packet capture on the pfSense WG interface. do you see the pings going both ways?

                  T 1 Reply Last reply Feb 14, 2024, 8:05 PM Reply Quote 0
                  • T
                    technoblue @Jarhead
                    last edited by Feb 14, 2024, 8:05 PM

                    @Jarhead

                    MTU to 1420, done.

                    No, my other wireguard service is running in an Qnap router and it doesn´t allow me to use the wireguard as cllient, only server I think it doesn´t matter as I can reach the subnet 192.168.15.0/24 the Qnap LAN, the ping and trace rout works when in Pfsense i select LAN interface, the problem is when I want to reach it from my Bridge interface (MySwitch) which is the one i use.

                    edef5b09-63d5-4d56-99e9-40b05765166d-imagen.png

                    J 1 Reply Last reply Feb 15, 2024, 1:06 AM Reply Quote 0
                    • J
                      Jarhead @technoblue
                      last edited by Jarhead Feb 15, 2024, 1:08 AM Feb 15, 2024, 1:06 AM

                      @technoblue So then it's something on the pc itself.
                      Is the gateway set correctly?
                      Do you have Windows firewall enabled? If so, disable it.
                      Is the pc's network discovered as public or private?
                      Can the pc connect to anything else?

                      Just to clarify, Wireguard doesn't use Server/Client types. Everything is just a peer.
                      Although one peer can be used as a hub in a hub and spoke config (ie multisite) so it can be considered a server, but it's still just a peer.

                      T 1 Reply Last reply Feb 15, 2024, 3:35 PM Reply Quote 0
                      • T
                        technoblue @Jarhead
                        last edited by technoblue Feb 15, 2024, 4:26 PM Feb 15, 2024, 3:35 PM

                        @Jarhead

                        My Pc and my other devices in the network doesn`t have any issues, I think that the gateway is set correctly because in the ping and tracerout test works fine with "Any" or LAN Interfaces, the issue is when I try it with the "MYSWITCH" bridge interface (which is the one use)

                        71271113-7be3-423d-b424-d411cb5dce6a-image.png

                        Static Route:
                        68f077c0-af83-4fc6-85cd-0d5d766e6ee0-imagen.png

                        42cdfd45-7a33-4aa6-becc-69286934e106-image.png

                        94a101d1-5031-4137-b93d-6292b6441dcc-image.png

                        df9015db-5f2d-4e66-b81f-fde15dbdaad8-image.png

                        Thanks for the clarification.

                        1 Reply Last reply Reply Quote 0
                        • T
                          technoblue
                          last edited by Mar 4, 2024, 10:55 AM

                          Some idea? Someone?

                          1 Reply Last reply Reply Quote 0
                          • T
                            technoblue
                            last edited by Mar 23, 2024, 10:51 AM

                            Finally!

                            The solution was creating a firewall rule that route the traffic of my Bridge interface through the gateway i have created for the wireguard client.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              [[user:consent.lead]]
                              [[user:consent.not_received]]