Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tunnel offline - 100% packet loss

    Scheduled Pinned Locked Moved WireGuard
    4 Posts 2 Posters 309 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AndyRHA
      AndyRH
      last edited by AndyRH

      A friend and I have a WG tunnel between 2 pfSense FWs. It has worked well for over a year. A few days ago, it went off-line. Neither of us touched WG.
      When I do a packet capture, I can see the FWs pinging each other on the correct port, but the GW stays off-line.
      We have both restarted the WG service.
      We have both went through the settings to verify nothing was changed.
      Both sides are running 24.03

      What could go wrong? Where do I look?

      09:09:44.216872 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 148
      09:09:44.252887 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:09:44.254045 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:09:49.363877 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 148
      09:09:49.445027 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:09:49.446205 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:09:54.578324 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:09:54.579509 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:09:59.698243 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:09:59.699428 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:10:04.755018 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:10:04.756200 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:10:09.888127 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:10:09.889309 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      09:10:15.012695 IP 172.D.E.F.842 > 75.A.B.C.842: UDP, length 148
      09:10:15.013907 IP 75.A.B.C.842 > 172.D.E.F.842: UDP, length 92
      

      o||||o
      7100-1u

      1 Reply Last reply Reply Quote 0
      • AndyRHA
        AndyRH
        last edited by

        We have given up on Wireguard. No way to diagnose the problem when a working tunnel goes down and will not connect.
        Maybe in a few versions this will be fixed.

        So Sad.

        o||||o
        7100-1u

        M 1 Reply Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @AndyRH
          last edited by

          @AndyRH
          Sorry to see nobody helped you out Andy.
          If you are willing to give it a shot maybe i can take a peak at the issue with you?

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          AndyRHA 1 Reply Last reply Reply Quote 0
          • AndyRHA
            AndyRH @michmoor
            last edited by

            @michmoor Thanks but we have trashed it and will do OpenVPN even though it is slower, but more reliable and easier to troubleshoot.

            o||||o
            7100-1u

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.