OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • Port forwarding through WireGuard
« previous next »
  • Print
Pages: [1]

Author Topic: Port forwarding through WireGuard  (Read 2575 times)

frankw

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Port forwarding through WireGuard
« on: April 28, 2021, 10:42:54 pm »
Hi everyone,

I was wondering if anyone could assist me in configuring firewall rules to allow inbound connections through a Wireguard VPN.

I have set up 3 WG connections using this guide, and this works well. These connections are also load balanced in a gateway group, with traffic flowing through them.

What I would like to do is now allow incoming connections through these WG connections, and forward those requests to an internal IP. I have forwarded the ports at the VPN provider, and have added port forwarding rules on the WG interfaces, but have had no luck and ports still show as closed.

Any suggestions about where to look would be much appreciated.
« Last Edit: April 28, 2021, 10:48:06 pm by frankw »
Logged

frankw

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Port forwarding through WireGuard
« Reply #1 on: April 29, 2021, 02:43:57 am »
One thing that I have noticed is incoming connections being rejected on the WAN interface, which I don't really understand (as the traffic report shows the traffic going through the Wireguard interfaces)...
Logged

frankw

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Port forwarding through WireGuard
« Reply #2 on: April 29, 2021, 04:15:47 pm »
Have also followed this guide, and am still seeing incoming traffic hitting the WAN (and being rejected), rather than coming in on the WG interfaces...very odd.

https://nguvu.org/pfsense/pfsense-port-forward/

I am wondering if WireGuard behaves in a different way than OpenVPN when it comes to incoming connections...?
Logged

SebbesApa

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: Port forwarding through WireGuard
« Reply #3 on: April 29, 2021, 08:25:56 pm »
So the connection to your VPN provider works accept the port forwarding?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6348
  • Karma: 437
    • View Profile
Re: Port forwarding through WireGuard
« Reply #4 on: April 29, 2021, 08:58:35 pm »
Have you tried the -kmod variant, it may solve this
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

frankw

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Port forwarding through WireGuard
« Reply #5 on: April 30, 2021, 02:31:43 pm »
Quote from: SebbesApa on April 29, 2021, 08:25:56 pm
So the connection to your VPN provider works accept the port forwarding?
Yes it all works well except for the port forwarding. Traffic flows, but Torrent client can't accept incoming connections.

Quote from: mimugmail on April 29, 2021, 08:58:35 pm
Have you tried the -kmod variant, it may solve this
Yes I am using the kernel mod at the moment, it is much faster, but I can't get port forwarding to work no matter what I try :(
« Last Edit: April 30, 2021, 02:33:20 pm by frankw »
Logged

frankw

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Port forwarding through WireGuard
« Reply #6 on: May 02, 2021, 02:03:23 am »
Can confirm port forwarding does not work through WireGuard kmod with TorGuard, OpenVPN with the exact same firewall port forwarding rules works fine.

Github issue here is closed?

Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.1 Legacy Series »
  • Port forwarding through WireGuard
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2