Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
How to force wireguard egress through specific gateway?
« previous
next »
Print
Pages: [
1
]
Author
Topic: How to force wireguard egress through specific gateway? (Read 1230 times)
schmuessla
Newbie
Posts: 49
Karma: 1
How to force wireguard egress through specific gateway?
«
on:
November 10, 2023, 05:37:02 pm »
I have a Multi WAN setup here. Primary connection is via DSL, backup via mobile network.
Everything works fine. If DSL goes down everything is routed via mobile network. However when DSL up goes up again the wireguard tunnel remains active on mobile network. This is the intended behaviour I think (sticky connections).
What options do I have if I want to switch back to DSL connection? Forcing a specific gateway and losing tunnel when DSL is down would also be fine.
Logged
tracerrx
Full Member
Posts: 128
Karma: 11
Re: How to force wireguard egress through specific gateway?
«
Reply #1 on:
November 10, 2023, 05:42:00 pm »
In your firewall rules you can select the GATEWAY. This should force that traffic to use the specified gateway...
The gateway dropdown is towards the bottom of the firewall edit/add screeen.
Logged
schmuessla
Newbie
Posts: 49
Karma: 1
Re: How to force wireguard egress through specific gateway?
«
Reply #2 on:
November 10, 2023, 05:55:15 pm »
You mean the Interface specific firewall rules?
I think that doesn't work because everything needs to go through the tunnel, or did I miss something?
Logged
tracerrx
Full Member
Posts: 128
Karma: 11
Re: How to force wireguard egress through specific gateway?
«
Reply #3 on:
November 10, 2023, 05:59:19 pm »
Yes, the interface specific firewall rule...
Logged
schmuessla
Newbie
Posts: 49
Karma: 1
Re: How to force wireguard egress through specific gateway?
«
Reply #4 on:
November 11, 2023, 08:18:49 am »
Hm I played with rules but it seems they don't influence the gateway wg picks.
Logged
marcquark
Full Member
Posts: 103
Karma: 5
Re: How to force wireguard egress through specific gateway?
«
Reply #5 on:
November 11, 2023, 09:05:46 am »
You could disable default gateway switching so opnsense will always use the primary line. Then use gateway groups and firewall rules to handle failover for clients. Could work but means your tunnel loses the benefits of redundancy
Wasn't there, at some point, an option somewhere to reset firewall states on gateway failover? That should do the trick, but i can't find it...
/e: I'm not crazy, it used to be there. But apparently that also only worked one-way. See
https://forum.opnsense.org/index.php?topic=25818.0
and
https://github.com/opnsense/core/issues/5387
I guess a custom script that checks for this condition and resets the WG tunnel if necessary is an option? Cronjobs don't allow custom scripts anymore, but monit does. So you could try your luck with that and selectively killing the tunnel's firewall state, should kick it back into using the primary gateway
«
Last Edit: November 11, 2023, 09:12:41 am by marcquark
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
How to force wireguard egress through specific gateway?