• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Gateway Monitoring Failure after Restart

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 3 Posters 195 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    BrianBG
    last edited by Mar 21, 2025, 9:45 PM

    Hello Everyone,
    I have an interesting problem and was hoping people here could help me. I am running 2.7.2 and it has been working fairly flawlessly. I have 4 Wireguard Tunnels for over two years with functioning interfaces, tunnels, etc. For over a year I have been using an external monitor IP for each gateway, like 1.1.1.1.

    Lately, upon reboot, all of my Wireguard gateways are down with 100% packet loss. The tunnels are up and working according to Wireguard status.

    However, If I go in to each of the gateways, delete the Monitor IPs, save, apply changes, then immediately go back in and add back the monitor IPs, then they work. This only seems to be a problem on reboot, and only recently. Any idea what the problem is or what I can do? While it sounds a little whiney, I want my router to be able to reboot without me always having to go in and manually reset the monitor ips. Thanks in advance.

    L 1 Reply Last reply Mar 22, 2025, 8:40 AM Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Mar 21, 2025, 11:15 PM

      Do the WG tunnels have unique gateway IPs? Do you see any errors at boot?

      B 1 Reply Last reply Mar 22, 2025, 10:02 PM Reply Quote 0
      • L
        lcbbcl @BrianBG
        last edited by Mar 22, 2025, 8:40 AM

        @BrianBG I had the same problem. I don't know if it a bug but if i set as gw the wg interface ip and i don't use to external monitor. Also on the wg inferface CIDR is /32 is working.

        B 1 Reply Last reply Mar 22, 2025, 9:50 PM Reply Quote 0
        • B
          BrianBG @lcbbcl
          last edited by Mar 22, 2025, 9:50 PM

          @lcbbcl Thanks for this answer, but then it is pinging itself and sometimes the tunnel can be “up” but not permitting traffic. I like the external IP and it works well. You are right though, I will have to go this route if I can’t solve it.

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Mar 22, 2025, 9:54 PM

            Hmm, I had assumed he meant the remote WG interface IP? If not then, yeah there's no point monitoring the local IP. You might as well just disable monitoring in that case.

            L 1 Reply Last reply Mar 22, 2025, 10:04 PM Reply Quote 0
            • B
              BrianBG @stephenw10
              last edited by Mar 22, 2025, 10:02 PM

              @stephenw10 Where do I see Wireguard logs? I don’t see them under System Logs.

              1 Reply Last reply Reply Quote 0
              • L
                lcbbcl @stephenw10
                last edited by Mar 22, 2025, 10:04 PM

                @stephenw10 Well i use wg this way because for rare circumstances i need to use wg tunel inside a tailscale tunel. And if i don't remove external monitoring for wg i will have a routing loop. Also for tailscale outbound is not a good idea to bind tailscale ip to localhost

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Mar 22, 2025, 11:18 PM

                  Wireguard produces almost no logs which makes troubleshooting....interesting! So there are no WG specific logs. You can only see the interfaces connection in the system logs or check the states for passing traffic etc.

                  1 Reply Last reply Reply Quote 0
                  1 out of 8
                  • First post
                    1/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received