OPNsense Forum

English Forums => 25.7, 25.10 Series => Topic started by: hansdampf on September 02, 2025, 11:18:53 AM

Title: wireguard export client option
Post by: hansdampf on September 02, 2025, 11:18:53 AM
Is there any chance to get an export option for wireguard clients? Like its done for openvpn?

Thanks very much!
Title: Re: wireguard export client option
Post by: Patrick M. Hausen on September 02, 2025, 12:43:23 PM
You mean like the existing peer generator?
Title: Re: wireguard export client option
Post by: hansdampf on September 05, 2025, 10:09:31 AM
No, more like exporting the config-files.
Title: Re: wireguard export client option
Post by: borys.ohnsorge on September 05, 2025, 11:23:04 AM
It will be nice to have an option "Send config/QR Code by email" or download from User Portal in Business Edition like for OpenVPN.
Title: Re: wireguard export client option
Post by: meyergru on September 05, 2025, 11:30:50 AM
This. Or, as an alternative, publish it on the internet.

(This posting may contain traces of sarcasm)
Title: Re: wireguard export client option
Post by: Patrick M. Hausen on September 05, 2025, 12:57:38 PM
Quote from: hansdampf on September 05, 2025, 10:09:31 AMNo, more like exporting the config-files.

But that's what the peer generator does - produce a config file for you:

(https://forum.opnsense.org/index.php?action=dlattach;attach=47468;image)
Title: Re: wireguard export client option
Post by: hansdampf on September 11, 2025, 01:54:00 PM
That export is only for new instances. I refer to existing instances.
Title: Re: wireguard export client option
Post by: meyergru on September 11, 2025, 05:34:48 PM
I can see only two possibilities here:

1. You have an existing entry that is already working and in use  by a client - so, you need no export function.
2. You have an existing entry that is not being used, because you failed to export it in the first place or did not import it on the client. In that case, you might well create a new entry with the generator, which creates an export and delete the old (unused) entry.

I.e.: existing entries never need to be exported, or am I missing something here?

BTW: Some peer generators show you the client configuration exactly once for security reasons and more often than not, it is not exportable from the client, either. Oh, and in case you did not know: You should use a client configuration on one client only.
Title: Re: wireguard export client option
Post by: agh1701 on September 11, 2025, 07:39:37 PM
It is sometimes necessary to change or fix the config after it is issued.  An export would be handy.