Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wiregard site to site don't work
« previous
next »
Print
Pages: [
1
]
Author
Topic: Wiregard site to site don't work (Read 1590 times)
freegate
Newbie
Posts: 19
Karma: 0
Wiregard site to site don't work
«
on:
February 24, 2023, 12:30:24 pm »
Hello everyone,
I configured two opnsense sites with Wireguard with separate LAN addresses 192.168.0.0/24 (site A) and 192.168.10.0/24 (site B). Peers are done correctly on both sides. The "handshake" is done on both sides.
However, the workstations on site B manage to see the workstations on site A, but the workstations on site A cannot ping those on site B. However, I have set the same firewall rules on both sides.
A client-server configuration on site B works, however. Surely there is something wrong. But I can't see what? An idea ?
Cordially.
Logged
Demusman
Sr. Member
Posts: 304
Karma: 13
Re: Wiregard site to site don't work
«
Reply #1 on:
February 24, 2023, 12:46:38 pm »
Did you add the correct allowed IP's on both ends?
Each end should have the opposite ends IP's.
Logged
freegate
Newbie
Posts: 19
Karma: 0
Re: Wiregard site to site don't work
«
Reply #2 on:
February 24, 2023, 12:58:11 pm »
Of course,
On the wireguard of site A, in allowed IP's, I set 192.168.10.0/24, and the IP of Wireguard B (10.8.0.2/32) and on the Wireguard of site B, I set 192.168.0.0 /24 as well as the IP on Wireguard A (10.8.0.1/32).
«
Last Edit: February 24, 2023, 01:01:53 pm by freegate
»
Logged
Demusman
Sr. Member
Posts: 304
Karma: 13
Re: Wiregard site to site don't work
«
Reply #3 on:
February 24, 2023, 01:46:38 pm »
Check the routes on site A.
Logged
freegate
Newbie
Posts: 19
Karma: 0
Re: Wiregard site to site don't work
«
Reply #4 on:
February 24, 2023, 01:53:30 pm »
Quote from: Demusman on February 24, 2023, 01:46:38 pm
Check the routes on site A.
Wireguard site A : 192.168.0.1
Wireguard site B : 192.168.10.254
A tracert 192.168.0.1 from site B to site A returns:
1 <1ms <1ms <1ms 192.168.10.254
2 2ms 2ms 2ms 192.168.0.1
A tracert 192.168.10.254 from site A to site B returns
1 <1ms <1ms <1ms 192.168.0.1
2 <1ms <1ms <1ms LIVEBOX [192.168.3.1]
3 * * * Request timed out.
192.168.3.1 is the local IP of internet provider's box on site A
«
Last Edit: February 24, 2023, 01:57:28 pm by freegate
»
Logged
Demusman
Sr. Member
Posts: 304
Karma: 13
Re: Wiregard site to site don't work
«
Reply #5 on:
February 24, 2023, 02:23:31 pm »
No, I meant check the routing table,
Logged
freegate
Newbie
Posts: 19
Karma: 0
Re: Wiregard site to site don't work
«
Reply #6 on:
February 24, 2023, 02:37:40 pm »
Quote from: Demusman on February 24, 2023, 02:23:31 pm
No, I meant check the routing table,
Ok but I'm sorry, I don't know how to do that.
Logged
Demusman
Sr. Member
Posts: 304
Karma: 13
Re: Wiregard site to site don't work
«
Reply #7 on:
February 24, 2023, 03:48:27 pm »
System/Routes/Status
Logged
freegate
Newbie
Posts: 19
Karma: 0
Re: Wiregard site to site don't work
«
Reply #8 on:
February 25, 2023, 04:42:26 am »
Status returns :
192.168.10.0/24 link#10 US NaN 1360 wg0 WG
Routing Table seems right, however ...
«
Last Edit: February 25, 2023, 06:48:57 pm by freegate
»
Logged
freegate
Newbie
Posts: 19
Karma: 0
Re: Wiregard site to site don't work
«
Reply #9 on:
February 27, 2023, 01:53:13 pm »
I found the solution.
The problem came from the LAN gateway which was not configured by default.
Demusman tipped me off
Thanks
«
Last Edit: February 27, 2023, 01:55:00 pm by freegate
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
Wiregard site to site don't work