Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wireguard does not start at boot time
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: Wireguard does not start at boot time (Read 3291 times)
brandl_it
Newbie
Posts: 21
Karma: 0
Wireguard does not start at boot time
«
on:
November 10, 2022, 09:04:16 am »
Hallo zusammen,
ich bin neu im Forum und kenne mich leider noch nicht ganz mit allen Funktionen aus. Entschuldigt bitte, sollte ich den Post falsch oder einen doppelten erstellen.
Wenn ich die Opnsense neu starte, wird der Wireguard Service nicht gestartet. Es scheint daran zu liegen, dass ich eine Site2Site Verbindung mit einem FQDN eingerichtet habe? Könnt Ihr den Fehler bestätigen bzw. wie kann ich diesen korrigieren?
Grüße
-----------------------------------------------------------------------------------------------------------------------------
Hello all,
I'm new to the forum and unfortunately I'm not quite familiar with all the features yet. Apologies if I create the post wrong or a duplicate.
When I restart the opnsense, the wireguard service does not start. It seems to be because I have a Site2Site connection set up with an FQDN? Can you confirm the error or how can I correct it?
Greetings
Logged
Patrick M. Hausen
Hero Member
Posts: 6926
Karma: 584
Re: Wireguard does not start at boot time
«
Reply #1 on:
November 10, 2022, 09:06:17 am »
Use an IP address for your peer instead of a hostname.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #2 on:
November 10, 2022, 09:08:35 am »
Wow, that was fast.
Is it not possible to work with a FQDN? For example: vpn.opensense.de?
The other side has a dynamic IP address. Unfortunately I have to work with a No-IP account.
Logged
franco
Administrator
Hero Member
Posts: 17715
Karma: 1618
Re: Wireguard does not start at boot time
«
Reply #3 on:
November 10, 2022, 09:36:02 am »
It depends on where you define your hostnames... If you use an external DNS server in your internal network which OPNsense is supposed to query always it works a lot better than trying to start a VPN during a boot sequence that may or may not have access to root servers yet.
It depends on the employed routing and DNS behaviour A LOT.
Cheers,
Franco
Logged
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #4 on:
November 10, 2022, 10:16:41 am »
Hello Franco,
I have the hostname for the endpoint under: Wireguard -> Endpoint -> Endpoint Address defined. I used the Opnsense as DNS server in the internal network. Furthermore I configured DNS over TLS via the Cloudfare servers.
Greetings
Logged
franco
Administrator
Hero Member
Posts: 17715
Karma: 1618
Re: Wireguard does not start at boot time
«
Reply #5 on:
November 10, 2022, 10:22:25 am »
The trouble starts with e.g. DHCP not coming up early enough during boot to provide you with DNS. I suppose you do not have a static WAN setup...
Cheers,
Franco
Logged
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #6 on:
November 10, 2022, 10:29:33 am »
No, I do not have a static IP connection. My internet connection is via PPPOE. I.e.: that the start of Wireguard is faster than the DNS system and therefore the service can not start properly, because it can not resolve the FQDN of a VPN tunnel?
Greetings
Logged
franco
Administrator
Hero Member
Posts: 17715
Karma: 1618
Re: Wireguard does not start at boot time
«
Reply #7 on:
November 10, 2022, 10:39:41 am »
That's likely. PPPoE can be especially slow in this regard.
Additionally, the WireGuard plugin appears to not register a facility to restart on IP address changes which is needed for this to work in the first place. That maybe the easier part to solve.
Cheers,
Franco
Logged
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #8 on:
November 10, 2022, 11:05:20 am »
Hello Franco,
What would be your recommendation to solve the problem? Do you happen to know if this issue will be fixed in an update?
Regards
Logged
franco
Administrator
Hero Member
Posts: 17715
Karma: 1618
Re: Wireguard does not start at boot time
«
Reply #9 on:
November 10, 2022, 11:13:24 am »
It would be best to raise a ticket over at
https://github.com/opnsense/plugins/issues/new?assignees=&labels=&template=feature_request.md&title=
and reference this topic.
Cheers,
Franco
Logged
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #10 on:
November 10, 2022, 11:26:00 am »
Thanks very much! I opened an issue:
https://github.com/opnsense/plugins/issues/3186
Logged
franco
Administrator
Hero Member
Posts: 17715
Karma: 1618
Re: Wireguard does not start at boot time
«
Reply #11 on:
November 10, 2022, 11:35:55 am »
thank you
Logged
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #12 on:
November 12, 2022, 01:53:08 pm »
Hello,
the described behavior of Wireguard is unfortunately normal at the moment. I have also talked to colleagues again. The problem also exists in the same form with Mikrotik or under Linux directly. So for the moment I will continue to stay with Openvpn. I use some VPN Site2Site connections with dynamic IP. Under Openvpn this works without problems.
Greetings
Logged
chemlud
Hero Member
Posts: 2488
Karma: 112
Re: Wireguard does not start at boot time
«
Reply #13 on:
November 12, 2022, 01:57:14 pm »
Did you try to set up the Cron job for restarting stale WG tunnels (provided in the GUI) and it didn't help?
https://forum.opnsense.org/index.php?topic=21659.msg149147#msg149147
Here It works just fine for me...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
brandl_it
Newbie
Posts: 21
Karma: 0
Re: Wireguard does not start at boot time
«
Reply #14 on:
November 12, 2022, 03:18:10 pm »
Hi,
no, I have not tested that. Thanks!
Honestly, I must confess, I find it a great pity that Wireguard does not simply try to connect again.
Greetings
Logged
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wireguard does not start at boot time