Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Mullvad VPN enable/re-enable functionality - 0.01 BTC

    Scheduled Pinned Locked Moved Bounties
    11 Posts 2 Posters 316 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • tinfoilmattT Offline
      tinfoilmatt LAYER 8
      last edited by

      I have a CE host with Mullvad WG tunnels that come up normally at boot (save for a few expected 'interface out' errors, presumably before the system is fully initialized). Need more info about your config, and preferably some screencaps of what you're looking at, to effectively troubleshoot.

      block out log on { ix0 } inet from any to any
      block out log on { ix0 } inet6 from any to any

      J 1 Reply Last reply Reply Quote 0
      • J Offline
        jupitersetting @tinfoilmatt
        last edited by jupitersetting

        @tinfoilmatt

        I followed this guide to setting up the Mullvad VPN via Wireguard using pfSense to the letter with pfSense 2.8.1.

        As noted, the Mullvad VPN tunnel works fine, but in order for it to work, I need to manually intervene each time the router is booted by disabling the OPT1 interface, and then re-enabling the OPT1 interface. The purpose of the bounty is to remove this inconvenience.

        The attached photos show how I address this problem manually using the pfSense GUI. I'm hoping that someone on here might understand how to perform the same step, but in a programmable manner, so that I can run a startup shell script each time the router boots, saving me the hassle of needing to manually login to the router with my browser every time it boots up.opt1_off.png opt1_on.png

        tinfoilmattT 1 Reply Last reply Reply Quote 0
        • tinfoilmattT Offline
          tinfoilmatt LAYER 8 @jupitersetting
          last edited by

          Neither your bounty nor your manual intervention is necessary to make this work.

          block out log on { ix0 } inet from any to any
          block out log on { ix0 } inet6 from any to any

          J 1 Reply Last reply Reply Quote 0
          • J Offline
            jupitersetting @tinfoilmatt
            last edited by

            @tinfoilmatt I need to perform the manual intervention (described above) every time I boot up the router, otherwise I am not connected to the Mullvad tunnel. Without the manual intervention, pfSense does not connect me to the internet through the Mullvad tunnel.

            A program would perform automatically what I now have to do manually, and would solve my problem, but I'm not familiar enough with pfSense to write that program. Hence I am asking for the help of someone who is familiar with pfSense. The bounty reward is offered as an incentive.

            tinfoilmattT 1 Reply Last reply Reply Quote 0
            • tinfoilmattT Offline
              tinfoilmatt LAYER 8 @jupitersetting
              last edited by

              Without the manual intervention, pfSense does not connect me to the internet through the Mullvad tunnel.

              Then you have a misconfiguration.

              block out log on { ix0 } inet from any to any
              block out log on { ix0 } inet6 from any to any

              J 1 Reply Last reply Reply Quote 0
              • J Offline
                jupitersetting @tinfoilmatt
                last edited by jupitersetting

                @tinfoilmatt I think it's important to note that I'm not changing any configuration settings. I am simply disabling and re-enabling the OPT1 interface. Once I do this manually, the connection works flawlessly. It is akin to powering off and powering on a computer without changing any of the settings or files, but now the computer boots up flawlessly.

                As noted, I followed the Mullvad guide to the letter, double and triple checking each setting. Furthermore, the fact that the Mullvad connection works great (after I perform the manual reset), indicates that the configuration is not broken.

                My uninformed guess is that it is some sort of race condition within pfSense/Wireguard/Mullvad, that occurs when my router is booted. By performing a manual reset of the OPT1 interface, I effectively bypass this race condition.

                Determing the cause of the race condition seems too challenging and is probably not worth the effort. But I think there's a good chance there's a knowledable person on here who knows how to find the answer to my question, because all I'm trying to do is replicate a pre-existing function. I may end up looking into the pfSense source code myself for the answer if nobody else figures it out, but for now, I'm content to see if there's a knowledgable person out there who is interested in winning the bounty and saving me a lot of extra work.

                tinfoilmattT 1 Reply Last reply Reply Quote 0
                • tinfoilmattT Offline
                  tinfoilmatt LAYER 8 @jupitersetting
                  last edited by

                  What kind of hardware?

                  block out log on { ix0 } inet from any to any
                  block out log on { ix0 } inet6 from any to any

                  J 1 Reply Last reply Reply Quote 0
                  • J Offline
                    jupitersetting @tinfoilmatt
                    last edited by

                    @tinfoilmatt For security purposes, I have selected to not provide any unique hardware, software, or network specifications.

                    tinfoilmattT 1 Reply Last reply Reply Quote 0
                    • tinfoilmattT Offline
                      tinfoilmatt LAYER 8 @jupitersetting
                      last edited by

                      Your network can't be that secure if you're spitting out all kinds of signals to ISP before manually bringing up your tunnel.

                      .01 BTC up front and another .01 BTC after, and I'll fix up your 'to the letter' work!

                      block out log on { ix0 } inet from any to any
                      block out log on { ix0 } inet6 from any to any

                      J 1 Reply Last reply Reply Quote 0
                      • J Offline
                        jupitersetting @tinfoilmatt
                        last edited by

                        Thank you for your consideration. This bounty is closed.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                        Privacy Policy · Cookie Policy