Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Virtual private networks
»
[WIREGUARD] Site to Site doesn't work
« previous
next »
Print
Pages: [
1
]
Author
Topic: [WIREGUARD] Site to Site doesn't work (Read 1085 times)
Blacktime2
Newbie
Posts: 9
Karma: 0
[WIREGUARD] Site to Site doesn't work
«
on:
May 27, 2024, 05:54:57 pm »
Hello team,
I've been trying to set up a Wireguard tunnel between my two firewalls but I've run into a lot of problems and it's complicated to debug it.
You can see my network map in the attachment.
After configuring the tunnel, I can see that packets are being exchanged between the 2 firewalls, but the tunnel doesn't seem to be going up.
Here's everything I've configured:
- Instances on the 2 FWs
- Peer on the 2 FWs
- Open a UDP port on both sides
- Authorize the right IP ranges + open flows on the “Wireguard (Group)” interface
- Add a keep alive of 25 for NAT
Any ideas? It seems I'm not the only one with this problem on the forum. Is it a bug in the new version of wireguard?
Thanks to all those who will take the time to read me !
Logged
Bob.Dig
Sr. Member
Posts: 257
Karma: 13
Re: [WIREGUARD] Site to Site doesn't work
«
Reply #1 on:
May 28, 2024, 09:12:17 am »
Quote from: Blacktime2 on May 27, 2024, 05:54:57 pm
Is it a bug in the new version of wireguard?
No. Nice picture though.
Logged
Patrick M. Hausen
Hero Member
Posts: 6796
Karma: 571
Re: [WIREGUARD] Site to Site doesn't work
«
Reply #2 on:
May 28, 2024, 09:36:10 am »
Without your full wireguard configuration (minus private keys) and all corresponding firewall rules it is pretty hard to help you.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Blacktime2
Newbie
Posts: 9
Karma: 0
Re: [WIREGUARD] Site to Site doesn't work
«
Reply #3 on:
May 29, 2024, 04:46:13 pm »
Thank you for your reply. Here you can see the Wireguard configuration as an attachment.
Logged
Bob.Dig
Sr. Member
Posts: 257
Karma: 13
Re: [WIREGUARD] Site to Site doesn't work
«
Reply #4 on:
May 29, 2024, 08:01:15 pm »
The remote networks should be /24 or whatever they are, not /32 (allowed IPs).
Logged
Blacktime2
Newbie
Posts: 9
Karma: 0
Re: [WIREGUARD] Site to Site doesn't work
«
Reply #5 on:
May 29, 2024, 09:43:10 pm »
Okay, I just changed. But that's not the cause of the problem.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Virtual private networks
»
[WIREGUARD] Site to Site doesn't work