Wireguard Local Traffic only

Started by hagensieker, November 29, 2025, 08:35:10 PM

Previous topic - Next topic
I had set up WireGuard successfully a year or three ago on Opnsense.  Then one day it just stopped working.  I have filled the hole with Tailscale but I need to get rolling with WG again.

I did manage while I was away this weekend to set up a new WG instance and peer.  Connecting works and had a handshake issue.  I have a pass rule set up for the WG instance under Firewall > Rules.

All I am getting is local traffic only.  And that's fine.  When I travel I want access to my Home Assistant, TrueNAS, QNAP, etc.  It works perfect. I am not able to pass internet traffic though.

Only problem there is on another device (GL.Inet) travel router.   I need the magic firewall rule or setting to accomplish.  Somebody please let me know what I'm missing.  Peer on Wireguard client:

[Interface]
PrivateKey = redacted=
ListenPort = 51820
Address = 10.10.10.2/24

[Peer]
PublicKey = redacted=
AllowedIPs = 0.0.0.0/0,::/0
Endpoint = 195.252.xxx.xxx:51820
PersistentKeepalive = 25

Again this passes local traffic.  I deleted DNS and have played with a few entries.

Pretty sure I need to tweak a firewall rule but not sure

Show the rules you have?

Regards,
S.
Networking is love. You may hate it, but in the end, you always come back to it.

OPNSense HW
APU2D2 - deceased
N5105 - i226-V | Patriot 2x8G 3200 DDR4 | L 790 512G - VM HA(SOON)
N100   - i226-V | Crucial 16G  4800 DDR5 | S 980 500G - PROD