Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
simple Wireguard Road Warrior config by docs no handshake
« previous
next »
Print
Pages: [
1
]
Author
Topic: simple Wireguard Road Warrior config by docs no handshake (Read 10191 times)
spkrb7
Newbie
Posts: 7
Karma: 0
simple Wireguard Road Warrior config by docs no handshake
«
on:
October 03, 2020, 05:44:33 am »
Trying to setup WG for remote access but handshake is not happening. The log from my phone has: "WireGuard/GoBackend/wgopnsense: peer(public key) - Handshake did not complete after 5 second, retrying after 5 seconds, retrying (try 2)". I'm using the officlal opnsense docs for setup. Any help appreciated.
Logged
OPNsense 20.7.3
Protetcli FW4
Asus RT-AC86U (AP)
mimugmail
Hero Member
Posts: 6763
Karma: 494
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #1 on:
October 03, 2020, 06:18:36 am »
Screenshots please
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
spkrb7
Newbie
Posts: 7
Karma: 0
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #2 on:
October 03, 2020, 07:39:58 am »
Thanks, appreciate your time, my lan addy is 192.168.1.1.
https://imgur.com/a/iIn3q0a
Logged
OPNsense 20.7.3
Protetcli FW4
Asus RT-AC86U (AP)
mimugmail
Hero Member
Posts: 6763
Karma: 494
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #3 on:
October 03, 2020, 11:12:25 am »
What is the port forward for? Allow rule on WAN for wg Port is active?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
spkrb7
Newbie
Posts: 7
Karma: 0
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #4 on:
October 03, 2020, 12:17:07 pm »
Quote from: mimugmail on October 03, 2020, 11:12:25 am
What is the port forward for? Allow rule on WAN for wg Port is active?
The port forward in the NAT section is per the instructions for WAN to LAN. It doesn't have the green triangle arrow indicating enabled, don't know if that applies there. Rule allowing WAN for wg is active, tried both in and out.
Logged
OPNsense 20.7.3
Protetcli FW4
Asus RT-AC86U (AP)
mimugmail
Hero Member
Posts: 6763
Karma: 494
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #5 on:
October 03, 2020, 02:46:05 pm »
Where in the docs is this?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
spkrb7
Newbie
Posts: 7
Karma: 0
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #6 on:
October 03, 2020, 08:46:33 pm »
Step 2b:
https://wiki.opnsense.org/manual/how-tos/wireguard-client.html#step-2b-setup-firewall-rules
Logged
OPNsense 20.7.3
Protetcli FW4
Asus RT-AC86U (AP)
mimugmail
Hero Member
Posts: 6763
Karma: 494
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #7 on:
October 04, 2020, 07:53:48 am »
Hm, seems it was changed after I wrote the initial one, but will work too.
Instead for using mywireguardservice net in firewall alias, can you just insert the real network?
Since you have assigned the interface but didn't set the IP address (which is correct), OPNsense might have problems to detect this network because addresses are assigned when starting/stopping daemon
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
spkrb7
Newbie
Posts: 7
Karma: 0
Re: simple Wireguard Road Warrior config by docs no handshake
«
Reply #8 on:
October 04, 2020, 09:32:46 pm »
Thanks for the suggestions much appreciated, I just couldn't get the handshake to complete, so I reset to start over when I get time.
Logged
OPNsense 20.7.3
Protetcli FW4
Asus RT-AC86U (AP)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
simple Wireguard Road Warrior config by docs no handshake