Questions tagged [wireguard]

352 questions
1
vote
0 answers

Wireguard VPN not making handshake

I'm facing a trouble, I have a server with Wireguard configured, with the keys generated by wg command line. I've downloaded Wireguard for windows and put the public's server key on client peer, and public's cliente key on server Peer section. Mu…
1
vote
0 answers

Access servers http via VPN

I have 2 VPS. On one of VPS lets call it A i setup Wireguard vpn. I connected my second VPS as peer to VPS A, also im connecting as client to Wireguard and cant access any web via local vpn address on server B. Nginx logs shows that server B took my…
1
vote
0 answers

Is it bad idea that all user and all devices connect to one WireGuard VPN interface?

I have few knowledge for network, I need some basic advice. On my business domain, users is facility manager or system installer. There are not many users and they can have some responsibility for security. My devices are made by Raspberry Pi that…
hando han
  • 11
  • 2
1
vote
0 answers

WireGuard slow routing?

I've got a setup as depicted in the picture. The problem is catastrophic speed when using routing. All WireGuard interfaces MTU = 1420. (1), (2) are debian servers. (3) is windows machine. The only setup done on (2) is net.ipv4.ip_forward = 1 CPU…
1
vote
0 answers

Cannot reach my external domains when connected to WireGuard VPN?

I have an Unraid server setup with services like WireGuard VPN, Home Assistant, Nginx Proxy Manager. The setup is as follows: WireGuard is running as "Remote tunneled access" with DNS server (192.168.1.1) which is my router. Home Assistant is…
1
vote
1 answer

How do I route all public traffic through Wireguard but not local traffic?

I know there's a series of CIDRs that I can use to cover all public CIDRs and leave out local CIDRs, but I cannot find this anywhere and I don't recall where I found it a couple of years ago when previously solving this problem. My goal is to have…
1
vote
1 answer

Can't access Fastly CDN sites through NAT

My office network nodes access internet via NAT (iptables masquerading) and the gateway server access internet using a Wireguard VPN connection. Everything works OK, but I can't access websites that are using Fastly CDN. Is there any additional…
Mez
  • 11
  • 1
1
vote
0 answers

Public IP address used instead of local IP as source address on Wireguard oet1 network interface

This is happening on Linux router. Any ideas why I've got public IP calling local IP on Wireguard network interface? Does it look right to you? Exactly those packets don't reach another Wireguard endpoint. Other packets work fine. Please see tcpdump…
laimison
  • 579
  • 2
  • 9
  • 17
1
vote
1 answer

Wireguard won't connect from one machine but will from another

I'm running Manjaro, in which I've set up a wireguard peer to connect to my raspberry pi at home, but it can't ping any machine on my local network, not even the wireguard peer. It may not even be connected, when it claims it is. I have a second…
Nate
  • 319
  • 2
  • 3
  • 8
1
vote
0 answers

Poor forwarding performance between two WireGuard tunnels

I've got a dedicated server (Ubuntu Server 20.04), running two WireGuard interfaces: wg0 is used to connect end-users, like laptops, mobile devices, etc. wg1 is a tunnel to a 3rd-party VPN service wg1 is set as the default route on the server…
dusty
  • 296
  • 1
  • 4
1
vote
2 answers

WireGuard routes and lokal route are overlapping

I have asked this question before but did not get a proper answer. I have a Debian machine that often changes its networks, so I rely on DHCP and cannot set a static route. So DCHP automatically creates two IP routes: The default route (0.0.0.0/0 →…
Jonathan
  • 43
  • 6
1
vote
1 answer

What do these nftables rules, as set up by wg-quick, mean?

I am using wg-quick to open a VPN connection. I can see the utility is setting some nft rules and I would like to understand them. I have moderate knowledge of iptables but none of nftables. Here is the Wireguard config file: [Interface] PrivateKey…
Patrick
  • 65
  • 8
1
vote
1 answer

Access wireguard using hardware Authentication like yubikey

At our company we use wireguard vpn to access our cluster. In our server, we install wireguard which will add a network interface that acts as a tunnel interface. The access with this tunnel will be encrypted via private/public keys association…
1
vote
1 answer

Route all traffic through a WireGuard Hub and Spoke VPS (Nftables)

As mentioned in the title, I am using a WireGuard Hub and Spoke configuration to connect my network at home to RoadWarrior peers. Unfortunately I have no public IPv4 and v6 address at home and on the road, so I need the hub. So far the routing of…
Jonathan
  • 43
  • 6
1
vote
1 answer

Why can I ping client → server, but not server → client, in a Wireguard context?

I have Wireguard set up on an Arch server (the server is both on the LAN 192.168.10.0/24 network as 192.168.10.2, and the WG one (192.168.20.0/24, he is 192.168.20.0). I connect to this server from a client on the Internet (I will use client and…
WoJ
  • 3,607
  • 9
  • 49
  • 79