• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall Rules for Wireguard S2S VPN in a Multi-WAN Environment with Multiple LAN

Scheduled Pinned Locked Moved WireGuard
s2svpnwireguard
4 Posts 2 Posters 493 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    algo7
    last edited by algo7 Feb 10, 2025, 3:04 AM Feb 10, 2025, 3:03 AM

    I have a S2S WG VPN running for a while but recently I got another ISP connections for some redundancy in terms of general connectivity.

    I only have a single LAN so I setup a loadbalanced GW Group with both WAN1 and WAN2 on Tier 1. In the firewall rules of LAN on, I changed the "Default Allow Any Rule" on LAN from using "default (follows the system routing table)" to using the loadbalanced GW Group.

    Everything worked fine but the S2S VPN stopped working. After some googling, I managed to get it work by setting up another firewall rule , above the "Default Allow Any Rule", that routes everything destined to the remote site's LAN to use the "default (follows the system routing table)" in the rule's gateway settings.

    My question is, if I have multiple LAN interfaces, do I have to create such rule for each interface, or do a floating rule, in order for clients connected to those interfaces to be able to reach the remote site via the S2S VPN?

    B 1 Reply Last reply Feb 10, 2025, 1:32 PM Reply Quote 0
    • B
      Bob.Dig LAYER 8 @algo7
      last edited by Bob.Dig Feb 10, 2025, 2:15 PM Feb 10, 2025, 1:32 PM

      @algo7 said in Firewall Rules for Wireguard S2S VPN in a Multi-WAN Environment with Multiple LAN:

      My question

      With your changed rule you forced everything through the gatewaygroup. But your S2S is not reachable by WAN, it is reachable differently. So you need more rules or do it differently. One suggestion, keep "default" as the gateway in your LAN-rule and change the Default Gateway in SystemRoutingGateways to your new gatewaygroup.

      A 2 Replies Last reply Feb 10, 2025, 5:56 PM Reply Quote 0
      • A
        algo7 @Bob.Dig
        last edited by Feb 10, 2025, 5:56 PM

        @Bob-Dig I see. So setting the default gateway to the gateway group should do the trick in general?

        I was just a bit confused when watching this vid here from Lawrence Systems:

        https://youtu.be/acDvlzmsnaE?t=317&si=8e8gKj_7g9BsbEQh

        From 5:23 (link already set to start from there) to around 6:30, he changed the default LAN to Any rule to use the gateway group instead of changing the default gateway in the "Routing" tab.

        1 Reply Last reply Reply Quote 0
        • A
          algo7 @Bob.Dig
          last edited by Feb 11, 2025, 2:28 AM

          @Bob-Dig

          EDIT:

          Changing the default gateway under the "Routing" tab again caused the remote site to be inaccessible via the S2S VPN.

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received