Can't activate Single Gateway (VPN) for WireGuard

Started by foobar_infosec, March 02, 2020, 06:45:21 AM

Previous topic - Next topic
Describe the bug
I installed VPN clients (OpenConnect and Wireguard) following the publicly available tutorials. But can not activate them under gateways.

To Reproduce
Steps to reproduce the behavior:

Add WG client according to https://docs.opnsense.org/manual/how-tos/wireguard-client-azire.html
- Add gateway
- Try to activate gateway

Expected behavior
- Gateway should be able to activate but is always disabled.

Screenshots
Wireguard client is working:
![Image of WG cient]
(https://i.imgur.com/L2dosdc.png)

VLAN to be routed through Wirguard Client (not really relevant, just listing to give context)
![Image of VLAN interface]
(https://i.imgur.com/4uLzL79.png)

NAT rule for Wireguard Client
![Image of NAT]
(https://i.imgur.com/BB2L3v3.png)

Firewall rule to fwd to gateway
![Image of FW rule]
(https://i.imgur.com/i2NDgax.png)

!!!! Gateway that can not be activated:
![Image of boken gateway activation]
(https://i.imgur.com/OD7AsTF.png)

Relevant log files
I already tried to look at the logs, but they are empty.

File /var/log/gateways.log yielded no results.

Additional context
I tried removing, and creating it new, and I have the same issue with the OpenConnect VPN client, so I assume its no issue with WireGuard but with actual gateway logic.

Environment

OPNsense 19.7.10_1-amd64
FreeBSD 11.2-RELEASE-p16-HBSD
OpenSSL 1.0.2u 20 Dec 2019
AMD GX-412TC SOC (4 cores)

You are missing the gateways IP address for your Wireguard and OpenConnect gateways. They are mandatory to be able to activate the gateway.