Wireguard site to site with multi WAN

Started by erdeidominik99, August 24, 2026, 09:37:57 PM

Previous topic - Next topic
Hy! I have 2 WAN connections. I have a wireguard site to site connection which I want to use the second wan for outgoing connection, not the default route one. I know that wireguard uses the system routing tabl, I tried to set up a floating rule with no success, then set up an SNAT rule to change the source ip, it works now, the connection goes out at the second WAN, but if the primary WAN fails it is not working, because the interface is down. Static route to the remote site ip is not an option, because I have another services on that ip, which I need the WAN failover function. Is there a solution to use the second WAN for the wireguard connection?

I would be interested to see if you solve this. I have wanted to do the same. This is what I got to work:

WAN 1 = General Internet
WAN 2 = VPN Internet

WAN 1 Gateway got a weight of 200
WAN 2 Gateway got a weight of 100

Gateway Switching and such all configured. This allows Wireguard to use WAN 2 normally, and if WAN 2 goes down, it would then use WAN 1.

Created Gateway Group with WAN 1 Primary and WAN 2 Secondary.
Created a Firewall Rule on the LAN network using inverted destination so if it was not going to the internal or VPN networks, it would use the Gateway Group instead of the defaults.

Not sure this would work for you as it sounds like you might be hosting other services that require NAT. I also have not done this method on the latest version of OPNsense, so I do not know if this still works with the new rule and NAT structures.