• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can´t reach Wireguard subnet from bridge interface

Scheduled Pinned Locked Moved Routing and Multi WAN
9 Posts 3 Posters 832 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    technoblue
    last edited by Mar 20, 2024, 9:16 PM

    Can´t reach one wireguard subnet from the bridge interface.

    I have a Bridge interface called MYSWITCH( with ip 10.2.0.1) as my pfsense device have 5 ethernet ports and need 4 LAN ports.

    Already is configure a site to site wireguard vpn with the subnet 10.95.99.0/31

    The local network is 10.2.0.0/24 and the remote site network is 192.168.15.0/24

    After proper configurations, when a ping(from pfsense dashboard) test is done, i can reach the remote site network

    6887a8cb-5807-4201-83df-1401b55d5671-imagen.png

    But doing the same but from a device in the local network it fails, the same as if the ping test from pfsense dashboard is done selecting MYSWITCH interface

    957f73a5-8e6a-45db-a187-80fd3797df6c-imagen.png
    91258185-9ffe-4815-9554-31e6b91993fb-imagen.png

    Someone have any sugestion?

    V 1 Reply Last reply Mar 20, 2024, 9:58 PM Reply Quote 0
    • V
      viragomann @technoblue
      last edited by Mar 20, 2024, 9:58 PM

      @technoblue
      Ensure that the remote device allows access from outside of its subnet. By default this is blocked by the operating systems firewall.

      Also recheck the Wireguard settings on both sites and the firewall rules on the remote.

      T 1 Reply Last reply Mar 21, 2024, 8:22 PM Reply Quote 0
      • T
        technoblue @viragomann
        last edited by Mar 21, 2024, 8:22 PM

        @viragomann

        The remote site isn´t the problem, i can connect to the subnet from my pc with wireguard client with no issues.

        And the firewall rules is just one that allow all traffic

        1bde913c-d64f-414a-90e6-b2aa44ffa49e-1706958315542-0bcb5f9d-5625-47f2-9031-469decb5db89-imagen.png

        and this is the static route

        d7de2759-9436-4ec7-a889-13b9e91bd9bf-1706958113350-e533d622-75e9-4bf7-835a-7ed2574acd80-imagen.png

        The extrange thing is that the ping with the LAN interface works, but it doesn´t work with the bridge interface

        V 1 Reply Last reply Mar 22, 2024, 12:54 PM Reply Quote 0
        • V
          viragomann @technoblue
          last edited by Mar 22, 2024, 12:54 PM

          @technoblue said in Can´t reach Wireguard subnet from bridge interface:

          And the firewall rules is just one that allow all traffic

          I was talking about the remote site.

          The extrange thing is that the ping with the LAN interface works, but it doesn´t work with the bridge interface

          Reasons for this could be that the remote site is missing the proper route to your LAN or that the destination device (192.168.15.210) uses a different upstream gateway than the remote VPN endpoint.

          T 1 Reply Last reply Mar 22, 2024, 1:22 PM Reply Quote 0
          • T
            technoblue @viragomann
            last edited by technoblue Mar 22, 2024, 1:23 PM Mar 22, 2024, 1:22 PM

            @viragomann said in Can´t reach Wireguard subnet from bridge interface:

            I was talking about the remote site.

            The remote site works fine, I can connect with the wireguard client perfect

            @viragomann said in Can´t reach Wireguard subnet from bridge interface:

            Reasons for this could be that the remote site is missing the proper route to your LAN or that the destination device (192.168.15.210) uses a different upstream gateway than the remote VPN endpoint.

            But if the issue is in the remote site, i wouldn´t be able to connect to it subnet and i can do it with the wireguard client.+

            020bdbef-0d20-4536-b4aa-6a8bfcfec113-imagen.png

            72c7b67b-0937-41ef-bc7f-4031c0952551-imagen.png

            V 1 Reply Last reply Mar 22, 2024, 1:30 PM Reply Quote 0
            • V
              viragomann @technoblue
              last edited by Mar 22, 2024, 1:30 PM

              @technoblue said in Can´t reach Wireguard subnet from bridge interface:

              The remote site works fine, I can connect with the wireguard client perfect

              But if the issue is in the remote site, i wouldn´t be able to connect to it subnet and i can do it with the wireguard client.+

              So if you know that better anyway to trying to help is a waste of time.

              J 1 Reply Last reply Mar 22, 2024, 2:52 PM Reply Quote 0
              • J
                Jarhead @viragomann
                last edited by Mar 22, 2024, 2:52 PM

                @viragomann said in Can´t reach Wireguard subnet from bridge interface:

                @technoblue said in Can´t reach Wireguard subnet from bridge interface:

                The remote site works fine, I can connect with the wireguard client perfect

                But if the issue is in the remote site, i wouldn´t be able to connect to it subnet and i can do it with the wireguard client.+

                So if you know that better anyway to trying to help is a waste of time.

                Yup, I got to the same point in his other thread.

                V 1 Reply Last reply Mar 22, 2024, 3:24 PM Reply Quote 0
                • V
                  viragomann @Jarhead
                  last edited by Mar 22, 2024, 3:24 PM

                  @Jarhead said in Can´t reach Wireguard subnet from bridge interface:

                  Yup, I got to the same point in his other thread.

                  Thanks for confirmation. So I have to add a new line to my blacklist, was unsure before. 😉

                  1 Reply Last reply Reply Quote 0
                  • T
                    technoblue
                    last edited by Mar 23, 2024, 10:45 AM

                    Finally!
                    The solution was creating a firewall rule that route the traffic of my Bridge interface through the gateway i have created for the wireguard client.

                    1 Reply Last reply Reply Quote 0
                    1 out of 9
                    • First post
                      1/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received