Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Juuze

#1
Hello!

Since OPNsense version 23.7 and the introduction of Wireguard-kmod 2.x, I have the following problem:

My OPNsense firewall, which operates as a Wireguard client to my other OPNsense firewall which is a VPS in a datacenter, can't reconnect to the VPS OPNsense firewall after a WAN IP change.
My To-Do is to log in in from my local network onto my local OPNsense instance and then click on the restart button of my Wireguard instance to the VPS.
Then everything is working as intended, as long as my IP address stays.

The same issue exists when I reboot my firewall.
I first need to log in onto my local OPNsense firewall after a reboot and then click to restart the Wireguard service which covers the connection to the VPS OPNsense instance.

Do I have something miss-configured? Is that a common bug?
Both of my OPNsense firewalls are on the latest OPNsense 23.7.5.


Greetings from Germany.
#2
Hello mike8971267,

as I understood correctly you disabled the DHCPv6 Server for your LAN network and only enabled "Assisted"-Mode in the Route Advertisements?

Route Advertisements set to "Assisted"-Mode, the DHCPv6 Server is required, in my understanding, because you set those M and O flags.

Anyway I followed all of your steps but still it's impossible for me to get working IPv6 in my LAN interface. My clients get a external IPv6-Address but I can't reach anythin. I've checked if my IPv6-Prefix is set correctly.

The think that is confusing to me is that my IPv6-Address on my WAN interface says something like: "xxxx:yyyy:4b00:x::yyyy and my LAN interface get the IPv6-Address of something like xxxx:yyy:4b47:zzzz:: is that a problem with a /57 size? Could that be the problem why my routing doesn't work?
#3
Hello together,

I know there are other forum posts here on this OPNsense forum about this topic like this, but this forum post doesn't cover my current situation.
The problem I'm facing is that when I set "Allow manual adjustment of DHCPv6 and Router Advertisements" to enabled and I input my own DNS settings under Route Advertisements, my clients don't get a working IPv6-Address anymore.
I know this is down to my missing configuration of DHCPv6.My question is now how to configure my DHCPv6 correctly so that I get the same dynamic IPv6-Address distribution because I don't have a static IPv6-Address at home, just like I would use the "automatic" tracking of my WAN interface without "Allow manual adjustment of DHCPv6 and Router Advertisements" set to enabled.
Thanks for you help!