OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: Flappie on January 27, 2023, 03:59:36 PM

Title: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: Flappie on January 27, 2023, 03:59:36 PM
Hi,

Installed Opnsense 23.1 and imported my config from version 22.7.1
I installed "wireguard" (not wireguard-go as in the previous 22.7).

Howver, i'm missing the "Wireguard group" under firewall rules.
This group was still there with version 22.7.

So, all my WireGuard clients are connected however they can't access anything since al firewall rules are missing.
Title: Re: Wireguard "Group" missing in firewall rules
Post by: Flappie on January 27, 2023, 04:02:16 PM
FYI, removing os-wireguard and reinstalling os-wireguard-go brings back the group with the rules.
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: chemlud on January 27, 2023, 04:06:06 PM
Hi!

That sounds strange, as the kernel version of WG is supposed to work...
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: tiermutter on January 27, 2023, 04:12:09 PM
Everything's fine here. Updated from 22.7.11(_1) and the WG group still exists without any changes regarding the rules.
Title: Re: Wireguard "Group" missing in firewall rules
Post by: RedVortex on January 27, 2023, 04:29:30 PM
Quote from: Flappie on January 27, 2023, 04:02:16 PM
FYI, removing os-wireguard and reinstalling os-wireguard-go brings back the group with the rules.

I upgraded to 23.1, I did not reinstall from zero as you did and the group still is present. However, maybe this means something was handled by the wg-go plugin scripts when it is installed to create the group in the rules and maybe this isn't present anymore with the kmod. Just a theory...
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: mimugmail on January 27, 2023, 04:40:27 PM
Just edit one firewall rule and save again, then it will be there.
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: Flappie on January 27, 2023, 04:50:10 PM
Quote from: mimugmail on January 27, 2023, 04:40:27 PM
Just edit one firewall rule and save again, then it will be there.

How to edit when the rules/group are not visible?
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: tiermutter on January 27, 2023, 04:59:18 PM
Maybe you should edit any rule on any interface?!
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: mimugmail on January 27, 2023, 05:45:58 PM
Quote from: Flappie on January 27, 2023, 04:50:10 PM
Quote from: mimugmail on January 27, 2023, 04:40:27 PM
Just edit one firewall rule and save again, then it will be there.

How to edit when the rules/group are not visible?

Just edit an existing rule and after save Group will pop up
Title: Re: Wireguard "Group" missing in firewall rules with os-wireguard
Post by: yeraycito on January 27, 2023, 06:00:50 PM
Opnsense 23.1 fresh install - no restore backup config

all correct