Quote from: FraLem on February 02, 2025, 10:03:08 AMWireguard running as expected on our 25.1 deployment (just private Wireguard servers).
May I suggest to check firewall configuration on the Wireguard interface?
Hope this helps
I don't have any firewall config on that interface really - there are no rules (I don't want to accept any incoming traffic even if the provider theoretically allows it, which I don't think Nord do anyway), the interface is enabled but with very little config (the local IP is set in my Wireguard config and the gateway set via System/Gateways). But I removed everything and double-checked everything anyway.
Quote from: meyergru on February 02, 2025, 10:32:26 AMWireguard running fine, I get near line speed at 800 GBit/s via iperf3, just with one thread.This appears to have "solved" the issue. I picked a random server in Albania (which is their first country alphabetically, no other reason) and the performance came right back up to where it should be (around 0.4 seconds for the same HTTPS test I did above). So yeah, in this case looks like maybe some Cloudflare oddities that affected both NordVPN and ProtonVPN on their EU exit nodes.
And NordVPN runs at 1 GBit/s, so whatever the problem is, seems not to be Wireguard.
I have found that either peering or some kind of blocking at target sites sometimes bites me with Wireguard. Try changing the outlet server.
At some point I might come back and troubleshoot it further, but it looks like it's working fine for now and it was just coincidence that I noticed this right after upgrading OPNsense to 25.1.