Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - corsetwebbed

#1
Have you implemented a firewall rule (for the Wireguard Interface) to permit traffic from your Android device to your LAN if the above indicates connected?

Quote from: StarsAndBars on July 28, 2025, 09:25:58 PMWould anyone be willing to assist me with a "Road Warrior" VPN setup I am trying to use in WireGuard? I have tried to follow the guide found here:
https://homenetworkguy.com/how-to/configure-wireguard-opnsense/?utm_content=cmp-true gorilla tag

I have captured logs and screenshots, but in short, after making the connection to the VPN using my Android phone (and the official WireGuard client for it) I cannot ping any resources on the desired LAN I have made a VPN connection to.

I am just not sure what my next step(s) would be on how to further troubleshoot this. My OPNSense firewall is connected to the internet via a business class cable modem connection, and I have a public & static IP WAN address from my provider (68.188.xxx.xxx).

Thanks in advance, I am stumped right now and I am getting frustrated...
#2
This includes multiple bootstrap IPs for different TLS/HTTPS DNS services. I had completely forgotten about that, but I believe the IPv6 bootstrap was being used because I was on a home network that supported IPv6 and it hadn't affected me before.

Quote from: WaveSense on January 02, 2025, 08:41:08 PMWelp I figured it out, it doesn't look like I can delete my post so I'll just use this to let people know what it was in case anyone else runs into this issue. :)

So, I had the following block list in my Firewall:
https://github.com/hagezi/dns-blocklists/blob/main/ips/doh.txt geometry dash

Which contains numerous bootstrap IPs for various DNS over TLS/HTTPS services. I had totally forgotten about it, but the reason that it hadn't effected me before this is that I was on a home network that supported IPv6 - so I think the IPv6 bootstrap was being used instead. However I'm on a new network now that doesn't support IPv6, and so the only option it has to connect is via IPv4 - and thus it's now hitting this block list.

Anyway the fix was simple, I just made it so the specific IP for the DNS boostrap I'm using is allowed before this block list is hit on the priority list.