OPNsense Forum

English Forums => Virtual private networks => Topic started by: user27 on April 12, 2024, 01:40:30 PM

Title: Wireguard - (yet) another newbie struggling
Post by: user27 on April 12, 2024, 01:40:30 PM
  Hi

I'm a total n00b with OpnSense. but have got a functioning system with a single LAN on 192.168.1.x subnet

I have configured WG instance and can connect (ie: I see a handshake) my iPhone peer to the peer on OpnSense

But phone cannot access any LAN resources or access internet if WG tunnel is active

Feels like a routing issue between peer on OpnSense and LAN

WG peers are 50.x subnet and I do get the appropriate IP on phone when connected

FW rule is set to pass all incoming IPv4 traffic on Wireguard tunnel net interface

Have looked at numerous HowTos and the like and have followed them closely, but this last hurdle has me stumped

Can anyone advise? Any configs you need to see? (happy to supply)

Many thanks
Title: Re: Wireguard - (yet) another newbie struggling
Post by: user27 on April 12, 2024, 04:41:49 PM
OK so semi fixed, in that I can connect to LAN resources from iPhone peer over 4G using WireGuard

But that same peer does not then have access to internet (ie: back out again from behind OpnSense FW)

iPhone peer on 192.168.50.x, LAN is 1.x, DNS is 1.1

Presumably I'm missing a FW rule?
Title: Re: Wireguard - (yet) another newbie struggling [SOLVED]
Post by: user27 on April 14, 2024, 06:22:58 PM
Yep, was missing a route  ::)