I have set up a Wireguard tunnel on my OPNSense router so that I can connect remotely via this to my LAN. I am able to reach both the OPNsense router itself and clients/servers on my LAN. However, I cannot reach the WAN and the internet. Occasionally when travelling, it could be useful to access the internet and get my home IP.
I assume this is a simple firewall rule, but for the life of me, I have not managed to open up the access (I have always found the whole firewall rules topic very confusing). Does anyone else have the same configuration and a wokring WAN access rule?
Apart from a proper Wireguard configuration and a rule on the wg interface, which allow access to any destination, you need a source NAT rule like this:
interface: WAN
source: wg tunnel subnet
destination: any
translation: interface address (default)
Hi, the use case you are needing is called "Road Warrior". Check the official docs first: https://docs.opnsense.org/manual/how-tos/wireguard-client.html#wireguard-road-warrior-setup
If you have already configured a working tunnel the step required to route all traffic through this is setting the AllowedIPs=0.0.0.0/0 at the client configuration. This way, the client will use the tunnel as the default route for all traffic.
The firewall rule you need to pass the hole traffic, LAN and WAN, is the simplest one because you want to allow traffic to "any" destination. With this one rule you can accomplish that:
Interface: [your wireguard interface]
Action: pass
Direction: in
Protocol: any
Version: IPv4
Source: [the wireguard network]
Source port: any
Destination: any
Destination port: any
The client configuration should look like this:
[Interface]
PrivateKey = [your client private key]
Address = [your peer IP address]/32
DNS = [you may use your server tunnel address here and Unbound will resolve addresses]
MTU = 1420
[Peer]
PublicKey = [your VPN server public key]
Endpoint = [your VPN server public IP o URL]:51820
AllowedIPs = 0.0.0.0/0,::/0 <---note that you can redirect IPv4 and IPv6 traffic