OPNsense Forum

Archive => 20.1 Legacy Series => Topic started by: skywalker007 on February 16, 2020, 05:00:44 pm

Title: WireGuard interface assignment
Post by: skywalker007 on February 16, 2020, 05:00:44 pm
After long time pushing this out, I have started to migrate my road warriors over to WireGuard.
Quick question on the server side config:
The docu says:
(https://uploads.tapatalk-cdn.com/20200216/34b499ba5c1d621d8a72455e98fa6a0b.jpg)
Is that still necessary? The NAT setup also offers me the automatically created WireGuard Interface. Why can’t I use that instead of doing a new assignment?
Thanks!
Title: Re: WireGuard interface assignment
Post by: mimugmail on February 16, 2020, 05:43:14 pm
Can you post a screenshot what exactly you mean?
Title: Re: WireGuard interface assignment
Post by: skywalker007 on February 18, 2020, 07:17:47 am
Like this:
(https://uploads.tapatalk-cdn.com/20200218/4564c06395d2246bb1583d5f38912642.jpg)
WG0 is a manually assigned Interface according to the docu. The other one is auto created I guess. Does it matter which one to use? Why would I need to manually assign an interface anyway?
Thanks a lot!
Title: Re: WireGuard interface assignment
Post by: mimugmail on February 18, 2020, 09:13:31 am
You only need to assign If you so policy routing. If you just want wg Client reach the internet, unassign and use WireGuard net
Title: Re: WireGuard interface assignment
Post by: skywalker007 on February 18, 2020, 03:49:22 pm
thanks a lot, that answers the question. Might be worth adapting the documentation.
Title: Re: WireGuard interface assignment
Post by: mimugmail on February 18, 2020, 04:34:06 pm
I think it's clearly stated that assignment is optional for policy based routing?
Title: Re: WireGuard interface assignment
Post by: skywalker007 on February 18, 2020, 04:51:31 pm
Is that what you mean by “filter some streams out of it”? Ok. I read the chapter differently. For me it sounds like “ in any case where you want to route all traffic through vpn, assign an Interface manually.”  Sorry for being picky on this, but I just want to improve this with my feedback. 
Title: Re: WireGuard interface assignment
Post by: mimugmail on February 18, 2020, 05:03:04 pm
No, thats good, be picky :)
Indeed, it's some time ago when I wrote it down, maybe I'm wrong (was).

So can you verify it works also without assigning?

Title: Re: WireGuard interface assignment
Post by: skywalker007 on February 18, 2020, 05:14:19 pm
Thanks. I will.
Title: Re: WireGuard interface assignment
Post by: skywalker007 on February 20, 2020, 05:10:13 pm
No, thats good, be picky :)
Indeed, it's some time ago when I wrote it down, maybe I'm wrong (was).
So can you verify it works also without assigning?
It does work well without manual interface assignment.