OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: RamSense on December 28, 2022, 07:47:24 AM

Title: problem zenarmor with wireguard interface ipv4 and ipv6 enabled
Post by: RamSense on December 28, 2022, 07:47:24 AM
I am running:
OPNsense 22.7.10_2-amd64
FreeBSD 13.1-RELEASE-p5
OpenSSL 1.1.1s 1 Nov 2022
with zenarmor:
Engine Version:    1.12.2
App & Rules DB Version:    1.12.22122618

Interfaces Selection: LAN (igb1), LAN2 (igb2), WG (wg0)

Wireguard with ipv4 and ipv6.
ISP is fiber PPPoE

When having zenarmor with WG (wg0) in the interfaces selection selected, the ipleak.net and other test sites show no wireguard ipv6 ip. When i remove WG (wg0) from the Zenarmor interfaces, and test, all is working great and showing my ipv6 ip.

When having zenarmor with WG (wg0) in the interfaces selection selected, and I stop the wireguard plugin from the opnsense dashboard, my cpu jumps to 25% and never gets below it. Restarting WG does not help, cpu 25% and up.
I have been looking into the problem for over a week in my wireguard config, until now when i tried to see what else could be the case. Well as soon as i remove WG (wg0) from Zenarmor inferfaces selection all is working!

So it looks like zenarmor is bugging here.

Hoping you can replicate this (bug?) and resolve it.
for now i remove my WG (wg0) from the Zenarmor interfaces to let my system run like it should...
Title: Re: problem zenarmor with wireguard interface ipv4 and ipv6 enabled
Post by: sy on December 30, 2022, 06:31:26 PM
Hi,

We are looking into the logs and get back to you.
Title: Re: problem zenarmor with wireguard interface ipv4 and ipv6 enabled
Post by: RamSense on December 30, 2022, 06:47:24 PM
Thank you for your reply and help. Hope you can find what the problem is and if it is a little bug or has something to do with my config without me noticing it.