OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 24.7 Production Series »
  • From Wireguard failure to WAN address?
« previous next »
  • Print
Pages: [1]

Author Topic: From Wireguard failure to WAN address?  (Read 199 times)

Sky22019

  • Newbie
  • *
  • Posts: 15
  • Karma: 0
    • View Profile
From Wireguard failure to WAN address?
« on: November 13, 2024, 10:17:34 pm »
Hello,

Up until recently, I was able to connect to my opnsense wireguard vpn instance from outside my house using both my mobile and my laptop. I simply followed the steps as described in the official documentation.
Alas; this is no more the case. I can't get wireguard to work anymore. The only thing that changed is opnsense versions. Or maybe something else (that I don't know) from my ISP?

Opnsense appliance is behind a bridged modem/router provided by my ISP. My WAN connection is pppoe (credentials in opnsense) and I am using no-ip as a ddns service. I repeat; all this was working flawlessly.

While troubleshooting; I stumbled upon something else. When going to Interfaces --> Overview, my WAN interface shows the following:
device: pppoe0, link type: pppoe, IPV4 100.69.xxx.xx/32, gateway 10.106.xxx.xxx and my public IP (external) is something else.

Am I missing something here? Or is this all normal, and it's just my wireguard instance not configured properly?

Thanks in advance.
Logged

dseven

  • Sr. Member
  • ****
  • Posts: 338
  • Karma: 36
    • View Profile
Re: From Wireguard failure to WAN address?
« Reply #1 on: November 14, 2024, 09:32:46 am »
Your ISP has put you behind CGNAT. Ask them if they can give you a routable IP address (doesn't have to be static, but that might be the only option they offer). Otherwise you'll need to find a VPN solution that involves some third party - tailscale, something cloud-based, etc.
Logged

tiermutter

  • Hero Member
  • *****
  • Posts: 1103
  • Karma: 61
    • View Profile
Re: From Wireguard failure to WAN address?
« Reply #2 on: November 14, 2024, 01:12:07 pm »
Even with IPv4 CGNAT you can use IPv6 for establishing a VPN connection.
This needs v6 properly configured at least for WAN interface and v6 connectivity on client side.
Logged
i am not an expert... just trying to help...

Sky22019

  • Newbie
  • *
  • Posts: 15
  • Karma: 0
    • View Profile
Re: From Wireguard failure to WAN address?
« Reply #3 on: November 14, 2024, 10:29:05 pm »
Thanks for the responses.
Quick update on the situation.

I contacted my ISP and they fixed it. They actually said that this was not on purpose and they don't know if it's gonna happen again in the future. I think the line was: "The system for some reason hands out IPs in the 100.xx range."

Outrageous right?

ISP is Cosmote (Greece).

FYI
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 24.7 Production Series »
  • From Wireguard failure to WAN address?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2