OPNsense Forum

English Forums => Virtual private networks => Topic started by: dawidku on November 14, 2022, 08:52:25 PM

Title: WireGuard server - clients connect but no access to local LAN/Internet
Post by: dawidku on November 14, 2022, 08:52:25 PM
I've configured WireGuard server as per road warrior manual.
I have clients connecting to the server, can see them in OPNsense, handshakes etc.
but I am not able to access anything on local firewall network nor browse internet when tunel
is established.

See my firewall rule for WireGuard below, as you can see I tried with IP address as well as WireGuard address
as a source in the rule - no difference.

I checked loads of post all over but no solution works, can anyone advise?


Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: tiermutter on November 14, 2022, 09:27:51 PM
Check firewall logs if there is traffic blocked and if your WG allow any rule is hit.
If there is nothin in FW logs, something other is wrong (config?).
Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: chemlud on November 14, 2022, 09:31:30 PM
...e.g. check allowed nets in client config.
Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: dawidku on November 14, 2022, 09:44:01 PM
Only seeing the attached in FW logs on WG interface but still no access to local network...

What does this mean?

Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: dawidku on November 14, 2022, 09:47:12 PM
And this is client's config

[Interface]
PrivateKey = jhsfjshjfhd=
Address = 10.0.0.3/32

[Peer]
PublicKey = asjhfjashfhsjk=
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = MyPublicIP:51820
PersistentKeepalive = 25
Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: dawidku on November 15, 2022, 12:04:01 AM
OMG I am so sorry for wasting your time.

I have just realised that allowed network / IP needs to be added to the client configuration.

Added the below and all works, LAN access, Internet access, all good  :)

AllowedIPs = 0.0.0.0/0, 192.168.1.0/24
Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: tiermutter on November 15, 2022, 06:50:00 AM
I do not completely understand:
In your post allowd IPs is set to any (0.0.0.0/0)... so adding your LAN subnet additionally did the trick?
This is weird, because the LAN subnet is "part" of 0.0.0.0/0 which should work fine so far.
Is there no DNS server set in client config?
Title: Re: WireGuard server - clients connect but no access to local LAN/Internet
Post by: dawidku on November 15, 2022, 09:44:16 AM
Yes there is DNS set up in the client config but before adding 192.168.1.0/24 network
I wasn't able to access anything at all on LAN, not even OPNsense web interface.