Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
WireGuard Site-to-Site Setup with far-end break-out
« previous
next »
Print
Pages: [
1
]
Author
Topic: WireGuard Site-to-Site Setup with far-end break-out (Read 983 times)
MoonbeamFrame
Jr. Member
Posts: 71
Karma: 2
WireGuard Site-to-Site Setup with far-end break-out
«
on:
June 30, 2023, 01:45:53 am »
I have no problem in getting the Site-to-Site traffic passing.
But I'm having limited success on doing the far-end break-out, currently it is working from A to B, but not B to A.
I have not found anything in the forum, so could someone point me to any documentation that might help?
Thank you.
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1601
Karma: 176
Re: WireGuard Site-to-Site Setup with far-end break-out
«
Reply #1 on:
June 30, 2023, 09:28:32 am »
Could you provide a network diagram of what you try to do?
Logged
Hardware:
DEC740
MoonbeamFrame
Jr. Member
Posts: 71
Karma: 2
Re: WireGuard Site-to-Site Setup with far-end break-out
«
Reply #2 on:
July 01, 2023, 09:04:43 am »
Simplified diagram attached.
We have
- vlans A1 and B1 exchanging traffic
- vlans A2 and B2 isolated from each other
- vlan A1 able to use WAN B
I'm trying to get vlan B1 to be able to use WAN A
Site A is running OPNsense (my end). Site B is running Linux iptables.
At site A traffic from site B can be seen routing out via WAN A, but site B does not see the return traffic.
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1601
Karma: 176
Re: WireGuard Site-to-Site Setup with far-end break-out
«
Reply #3 on:
July 03, 2023, 08:50:21 am »
Does the wireguard tunnel config on both sides include:
Code:
[Select]
[Peer]
AllowedIPs = 0.0.0.0/0
Otherwise the wireguard tunnel drops packets with a public IPv4 address as destination.
I would use this tutorial to create a wireguard tunnel as a gateway:
https://docs.opnsense.org/manual/how-tos/wireguard-selective-routing.html
Logged
Hardware:
DEC740
MoonbeamFrame
Jr. Member
Posts: 71
Karma: 2
Re: WireGuard Site-to-Site Setup with far-end break-out
«
Reply #4 on:
July 03, 2023, 11:01:24 am »
Thanks.
0.0.0.0/0 Already set
And that was the tutorial I used when configuring the tunnel.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
WireGuard Site-to-Site Setup with far-end break-out