Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
OPNsense Wireguard S2S
« previous
next »
Print
Pages: [
1
]
Author
Topic: OPNsense Wireguard S2S (Read 1030 times)
spetrillo
Hero Member
Posts: 720
Karma: 8
OPNsense Wireguard S2S
«
on:
July 19, 2023, 12:16:13 am »
Hello all,
I have an OPNsense firewall on either side of what I want to be a S2S connection using Wireguard. On site A I am showing the following:
interface: wg2
public key:
private key: (hidden)
listening port: 51822
peer:
endpoint: :51824
allowed ips: 10.0.2.0/24, 10.0.1.0/24
transfer: 0 B received, 2.89 KiB sent
I am not seeing anything passed over wg2. Am I correct in that the interface wg2 is the router's interface and the peer is the other side? I never see wg2 listed in the handshake on the other side. What could I be doing wrong?
Thanks,
Steve
Logged
jomo79
Newbie
Posts: 1
Karma: 0
Re: OPNsense Wireguard S2S
«
Reply #1 on:
July 19, 2023, 12:52:39 am »
both sides on the same port and both sides the public key from the other side and it will work
Logged
spetrillo
Hero Member
Posts: 720
Karma: 8
Re: OPNsense Wireguard S2S
«
Reply #2 on:
July 23, 2023, 07:53:07 pm »
Do the IPs on each side need to be on the same subnet? Second on one side my OPNsense firewall is behind another firewall. Do I need to port forward from the firewall?
Logged
Patrick M. Hausen
Hero Member
Posts: 6745
Karma: 568
Re: OPNsense Wireguard S2S
«
Reply #3 on:
July 23, 2023, 07:57:27 pm »
The IP addresses of the tunnel interfaces or the IP addresses of the networks you want to connect?
1. You do not need IP addresses on the tunnel interfaces unless the firewalls themselves need to send traffic through the tunnel.
2. The networks you want to connect on both sides must be different and must not overlap.
3. If you use a network for the tunnel interfaces it also must be different and must not overlap.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
spetrillo
Hero Member
Posts: 720
Karma: 8
Re: OPNsense Wireguard S2S
«
Reply #4 on:
July 23, 2023, 08:08:06 pm »
OK so here is what I got:
Site A (My Home)
Listen Port: 51821
Tunnel Address: 10.0.0.3/24
Endpoint Allowed IPs: 10.0.1.0/24
Endpoint Port: 51821
This side comes up fine!
Site B (My Club)
Listen Port: 51821
Tunnel Address: 10.0.0.2/24
Endport Allowed IPs: 192.168.1.0/24, 192.168.2.0/24
Endpoint Port: 51821
This side does not come up and is behind another router!
I have a port forward on the first router at the club for UDP 51821. Do I need a port forward from the OPNsense router up to the first router's IP address?
Thanks,
Steve
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
OPNsense Wireguard S2S