OPNsense Forum

English Forums => Virtual private networks => Topic started by: kermitxyz on May 12, 2025, 11:42:01 PM

Title: Wireguard Site to Site
Post by: kermitxyz on May 12, 2025, 11:42:01 PM
I followed the official guide for Wireguard site to site VPN.

I have created the Wireguard instances and peers and they are handshaking, but I cannot send/receive to the remote LAN.

Do I need to create a Wireguard interface etc.?
Do I need to create routes somewhere?

The official guide doesn't mention either, but I can't ping the remote OPNSense router via the site to site VPN

(I am configuring it via a dial-in Wireguard VPN which does work fine - separate instance and port).

Any pointers much appreciated.
Title: Re: Wireguard Site to Site
Post by: wagman77 on May 14, 2025, 09:55:30 PM
I just have configured a wireguard site to site tunnel between two OPNSenses and I also followed the official howto.
In my setup, I have 2 WG interfaces, one for the Clients to "dial in" and the other one for the Site-to-Site connection.
You have to create a WG interface for each instance and enable it, if not, it won't work.