Use Wireguard from Inside the network

Started by PotatoCarl, Today at 09:11:39 AM

Previous topic - Next topic
Hi

I use in my setup a number of mobile devices running VPN clients in a local WIFI.

With OpenVPN it is no problem to stay connected with the VPN "inside" the local WIFI. With Wireguard I do not get any "Handshakes", i.e. it does not work. It works perfectly well from outside the "inside" network of the OPNSense router.

Is there any special setting in the firewall rules to use Wireguard from "inside"? The logging is unfortunately miserable so I have no idea why it does not work.

You could port forward your WireGuard port to localhost, take a look here.

WG works from LAN for me, without any port forwarding, or anything else special that I can think of... the typical default rule to allow from LAN to "any" should cover it, I think.

Don't you need some kind of NAT Loopback a.k.a. Reverse NAT trickery to be able to connect to your WAN IP Address from your LAN side ?!

In OPNsense language that would be NAT Reflection I think...
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

For some people, the WireGuard Endpoint is not the WAN-IP of Sense, for instance if you have another router in front of that.

Today at 05:39:47 PM #5 Last Edit: Today at 05:41:42 PM by nero355
Quote from: Bob.Dig on Today at 05:06:50 PMFor some people, the WireGuard Endpoint is not the WAN-IP of Sense, for instance if you have another router in front of that.
OK, but no one mentioned something like that ?!

And to be honest you have got to pick a very shitty ISP to have such an issue :
- For xDSL there is the DrayTek 167 or so Modem/Router which you could use in Bridge Modem configuration.
- For Cable a lot of ISPs offer a Bridge Mode of the Modem/Router they give to their customers.
- For Fiber connections there are multiple options :
Option A =>
AON connections are a matter of either inserting your SFP/SFP+ module into your OPNsense Router's SFP/SFP+ NIC or a Switch with SFP/SFP+ Ports and adding a little magic to get that connection to your OPNsense Router.
Option B =>
GPON/XGS-PON connections usually have simple Bridged ONTs if the ISP is not giving out "All-in-One" solutions.
And if it is you can usually buy a Bridged ONT from them or get one yourself and let them activate it on their network.

If all that fails then you are out of luck I guess... :)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: Bob.Dig on Today at 05:06:50 PMFor some people, the WireGuard Endpoint is not the WAN-IP of Sense, for instance if you have another router in front of that.

OK, but e.g. Fritzbox categorically refuses to do hairpin NAT. In that case you can use e.g. a host override in Unbound, pointing my.public.vpngw to the OPNsense WAN instead of the external router's WAN.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Today at 08:09:52 PM #7 Last Edit: Today at 08:39:29 PM by Bob.Dig
Quote from: Patrick M. Hausen on Today at 07:56:35 PMIn that case you can use e.g. a host override in Unbound, pointing my.public.vpngw to the OPNsense WAN instead of the external router's WAN.
True, but many WireGuard-apps don't update the address if it is already running.   

To be more precise, make a port forward of your WG-Port on your LAN, WiFi or whatever towards your public IP and redirect that to localhost.