Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Mullvad VPN enable/re-enable functionality - 0.01 BTC

    Scheduled Pinned Locked Moved Bounties
    11 Posts 2 Posters 313 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jupitersetting
      last edited by jupitersetting

      I asked this question a few days ago, but no one seems to know the answer. I am offering 0.01 Bitcoins to the person who can give me an answer that works.

      The challenge: I am trying to disable, and then re-enable the OPT1 mullvad interface in the same manner in which the GUI "Interfaces" menu accomplishes it, but doing so in a way I can easily run from a shell script. Doing it manually through the GUI Interfaces menu via "Enable interface" in the Interfaces menu is the only way I have been able to get the Mullvad VPN working with pfSense.

      I tried running:

      • /etc/rc.linkup stop/start
      • ifconfig mullvad down/up

      on the mullvad interface, but those commands by themselves don't connect me to the internet. This means that the GUI Interfaces menu is doing something else beyond what those two commands do, but I can't find anyone on the internet who seems to know how to replicate the "Enable Interface" functionality in a shell scripted manner.

      I will pay 0.01 bitcoins to whoever will teach me the shell commands necessary to replicate the on/off of the "Enable Interface" GUI functionality.

      Alternatively, if there is a different solution that someone knows that will get the Mullvad VPN started automatically every time the router boots, without needing additional manual GUI menu intervention, I will reward the 0.01 bitcoin to that person.

      Thank you in advance for your help.

      1 Reply Last reply Reply Quote 0
      • tinfoilmattT Offline
        tinfoilmatt LAYER 8
        last edited by

        I have a CE host with Mullvad WG tunnels that come up normally at boot (save for a few expected 'interface out' errors, presumably before the system is fully initialized). Need more info about your config, and preferably some screencaps of what you're looking at, to effectively troubleshoot.

        block out log on { ix0 } inet from any to any
        block out log on { ix0 } inet6 from any to any

        J 1 Reply Last reply Reply Quote 0
        • J Offline
          jupitersetting @tinfoilmatt
          last edited by jupitersetting

          @tinfoilmatt

          I followed this guide to setting up the Mullvad VPN via Wireguard using pfSense to the letter with pfSense 2.8.1.

          As noted, the Mullvad VPN tunnel works fine, but in order for it to work, I need to manually intervene each time the router is booted by disabling the OPT1 interface, and then re-enabling the OPT1 interface. The purpose of the bounty is to remove this inconvenience.

          The attached photos show how I address this problem manually using the pfSense GUI. I'm hoping that someone on here might understand how to perform the same step, but in a programmable manner, so that I can run a startup shell script each time the router boots, saving me the hassle of needing to manually login to the router with my browser every time it boots up.opt1_off.png opt1_on.png

          tinfoilmattT 1 Reply Last reply Reply Quote 0
          • tinfoilmattT Offline
            tinfoilmatt LAYER 8 @jupitersetting
            last edited by

            Neither your bounty nor your manual intervention is necessary to make this work.

            block out log on { ix0 } inet from any to any
            block out log on { ix0 } inet6 from any to any

            J 1 Reply Last reply Reply Quote 0
            • J Offline
              jupitersetting @tinfoilmatt
              last edited by

              @tinfoilmatt I need to perform the manual intervention (described above) every time I boot up the router, otherwise I am not connected to the Mullvad tunnel. Without the manual intervention, pfSense does not connect me to the internet through the Mullvad tunnel.

              A program would perform automatically what I now have to do manually, and would solve my problem, but I'm not familiar enough with pfSense to write that program. Hence I am asking for the help of someone who is familiar with pfSense. The bounty reward is offered as an incentive.

              tinfoilmattT 1 Reply Last reply Reply Quote 0
              • tinfoilmattT Offline
                tinfoilmatt LAYER 8 @jupitersetting
                last edited by

                Without the manual intervention, pfSense does not connect me to the internet through the Mullvad tunnel.

                Then you have a misconfiguration.

                block out log on { ix0 } inet from any to any
                block out log on { ix0 } inet6 from any to any

                J 1 Reply Last reply Reply Quote 0
                • J Offline
                  jupitersetting @tinfoilmatt
                  last edited by jupitersetting

                  @tinfoilmatt I think it's important to note that I'm not changing any configuration settings. I am simply disabling and re-enabling the OPT1 interface. Once I do this manually, the connection works flawlessly. It is akin to powering off and powering on a computer without changing any of the settings or files, but now the computer boots up flawlessly.

                  As noted, I followed the Mullvad guide to the letter, double and triple checking each setting. Furthermore, the fact that the Mullvad connection works great (after I perform the manual reset), indicates that the configuration is not broken.

                  My uninformed guess is that it is some sort of race condition within pfSense/Wireguard/Mullvad, that occurs when my router is booted. By performing a manual reset of the OPT1 interface, I effectively bypass this race condition.

                  Determing the cause of the race condition seems too challenging and is probably not worth the effort. But I think there's a good chance there's a knowledable person on here who knows how to find the answer to my question, because all I'm trying to do is replicate a pre-existing function. I may end up looking into the pfSense source code myself for the answer if nobody else figures it out, but for now, I'm content to see if there's a knowledgable person out there who is interested in winning the bounty and saving me a lot of extra work.

                  tinfoilmattT 1 Reply Last reply Reply Quote 0
                  • tinfoilmattT Offline
                    tinfoilmatt LAYER 8 @jupitersetting
                    last edited by

                    What kind of hardware?

                    block out log on { ix0 } inet from any to any
                    block out log on { ix0 } inet6 from any to any

                    J 1 Reply Last reply Reply Quote 0
                    • J Offline
                      jupitersetting @tinfoilmatt
                      last edited by

                      @tinfoilmatt For security purposes, I have selected to not provide any unique hardware, software, or network specifications.

                      tinfoilmattT 1 Reply Last reply Reply Quote 0
                      • tinfoilmattT Offline
                        tinfoilmatt LAYER 8 @jupitersetting
                        last edited by

                        Your network can't be that secure if you're spitting out all kinds of signals to ISP before manually bringing up your tunnel.

                        .01 BTC up front and another .01 BTC after, and I'll fix up your 'to the letter' work!

                        block out log on { ix0 } inet from any to any
                        block out log on { ix0 } inet6 from any to any

                        J 1 Reply Last reply Reply Quote 0
                        • J Offline
                          jupitersetting @tinfoilmatt
                          last edited by

                          Thank you for your consideration. This bounty is closed.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                          Privacy Policy · Cookie Policy