Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wireguard tunnel not staying up
« previous
next »
Print
Pages: [
1
]
Author
Topic: Wireguard tunnel not staying up (Read 3187 times)
Mantis314
Newbie
Posts: 15
Karma: 0
Wireguard tunnel not staying up
«
on:
August 03, 2021, 06:23:44 pm »
I have two sites both running Protectli appliances with OpnSense 21.1.9 installed.
I have Wireguard site to site VPN configured and working.
The VPN refuses to stay up for long though. It will only stay up for a couple of hours.
I have Keep Alive configured on both ends and set to 25.
The VPN-Wireguard-List Configuration and Handshakes tabs are blank on the remote end.
To get it working again I need to visit the Endpoints tab (on the remote firewall) and click Apply. It will come right back up and work for a couple more hours. Also at this point, the List Configuration and Handshakes tabs are populated again.
What do I need to do to keep the tunnel up?
Thanks in advance for any suggestions.
Mantis314
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Wireguard tunnel not staying up
«
Reply #1 on:
August 03, 2021, 07:27:48 pm »
Try keepalives at 5sec for testing
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #2 on:
August 04, 2021, 05:06:36 am »
Set the Keep Alive to 5 at both ends. It ran for over an hour. I went out to the grocery store this evening and when I returned it was down again.
Logged into the remote appliance,
Verified that List Configuration was blank again.
Verified that Handshakes was blank again.
Went to Endpoints and simply clicked Apply.
Seconds later List Configuration is populated as is Handshakes.
Tunnel is back up.
It will be down again in the morning.
It has been doing this since I first set it up a few months ago.
I don't get it.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Wireguard tunnel not staying up
«
Reply #3 on:
August 04, 2021, 06:45:21 am »
Screenshots of config please
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #4 on:
August 04, 2021, 11:44:33 pm »
These snips are of the end that drops, and were taken when the tunnel is up.
After it drops the list configuration and Handshakes go completely blank.
The local config has a field for DNS. I have tried with and without a DNS server here. I used 8.8.8.8
Mantis314
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Wireguard tunnel not staying up
«
Reply #5 on:
August 05, 2021, 07:16:52 am »
At Endpoint remove 192.168.19.0/24
It seems the daemon crashes for some reason.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #6 on:
August 06, 2021, 01:07:54 am »
I removed 192.168.19.0/24 from the Endpoint.
There is now only the relevant LAN subnet at each end.
I restarted the tunnel at 11:00 this morning.
When I returned home from work this afternoon at 4:00 it was down again in the same manner as before.
Going to Endpoints and clicking Apply Lights it back up again.
Are there any logs for Wireguard which might provide a clue as to what is happening?
Mantis314
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Wireguard tunnel not staying up
«
Reply #7 on:
August 06, 2021, 07:13:35 am »
Maybe you can plug in a display and watch the output
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #8 on:
August 06, 2021, 10:27:14 pm »
It's 200 miles away.
But I will be there over the weekend. I might try that.
Mantis
Logged
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #9 on:
August 13, 2021, 06:56:23 am »
I gave up on it.
It's just not worth all the frustration.
Tonight I built an IPSec tunnel instead.
Hoping that stays up.
Thanks for the support though, much appreciated!
Mantis314
Logged
chemlud
Hero Member
Posts: 2483
Karma: 112
Re: Wireguard tunnel not staying up
«
Reply #10 on:
August 13, 2021, 08:30:29 am »
just for testing I would start a cam stream over the tunnel and see if it remains stable. The IPs on both ends are stable?
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
Mantis314
Newbie
Posts: 15
Karma: 0
Re: Wireguard tunnel not staying up
«
Reply #11 on:
August 14, 2021, 06:25:59 am »
By the "IPs on both ends" I assume you mean the public WAN interface IPs.
Both ends are dynamic, and I use a dynamic DNS service to maintain hostname integrity.
Both IPs are stable in that neither address has changed in months.
I in fact tested using the IPs as opposed to the hostnames, but the outcome was the same.
The history of these two sites is that both ends were protected by old Sonicwalls (NSA-240 & TZ-100).
I had an IPSEC tunnel between the Sonicwalls which was quite reliable.
It has been about 24 hours now since I established an IPSec tunnel between the two OPNsense firewalls.
So far it is stable again.
My observation of the Wireguard is that, true to it's claim, it is very easy to set up and get running.
I never ran an iPerf test to see how much faster Wireguard was, but it did have a nice "feel" to it while it was up.
The Wireguard would not recover on it's own from a restart of either firewall. I always had to disable/enable it to get it running again.
And of course the site to site tunnel refused to stay up on it's own.
Mantis314
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Wireguard tunnel not staying up
«
Reply #12 on:
August 14, 2021, 08:49:29 am »
Hard to troubleshoot from remote, but you are also save and fast with IPsec
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wireguard tunnel not staying up