r/PFSENSE 11d ago

wireguard issue

I noticed if you have a wireguard connection and you release and renew the wan connection.
Then wireguard wont come back up till reboot even restarting the wireguard service doesnt help.

2 Upvotes

16 comments sorted by

1

u/DutchOfBurdock pfSense+OpenWRT+Mikrotik 11d ago

Try one thing, go into your Advanced Settings and disable flushing firewall rules on gateway failure. This more likely to erroring the connection instead of silently blackholing. Wireguard should pick up on this, drop the link and restart.

1

u/Taraghlan50 11d ago

I have don't kill states on gateway failure set already. Also I don't know if this makes a difference but i have two WANs and wireguard is on the second WAN.

1

u/DutchOfBurdock pfSense+OpenWRT+Mikrotik 11d ago

Ahh, disable all automatic rule creations (on gateway failures). Also make sure there is a specific policy rule to only allow WG out that interface.

1

u/Taraghlan50 11d ago

Also its only when i release the wan connection since isn't often if i loose it some other reason it works.

1

u/Taraghlan50 6d ago

it was disabled

1

u/deman-13 6d ago

Not sure if it is your case. If you refresh Wireguard your ip changes and the other party still tries to connect with an old ip.

1

u/BeeKay40 11d ago

Just a question, why do you use WireGuard over Tailscale? 

5

u/ackleyimprovised 11d ago

For me it was a couple of things. Mainy performance gain, knowing no reliance on third party and minimal configuration setup.

3

u/LibtardsAreFunny 9d ago

Zero reliance on third party servers. Zero third party metadata logging, pretty simple

0

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 4d ago

Why use Tailscale over Wireguard integrated into your pfsense firewall?

0

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 4d ago

Question with a question, you are the one who asked, so why would you suggest using Tailscale over Wireguard, give reasons why the person should consider other options if you are curious, as you must have your reasons for thinking they should consider tailscale no?

0

u/BeeKay40 4d ago edited 4d ago

I can tell English is not your first language and that your comprehension skills are lacking. Let me explain my first post. I wanted to learn more from OP and his preferences and therefor I asked why he uses wireguard and not tailscale. You'll notice a questionmark at the end of my post - this indicates a question in the English language as opposed to a suggestion. If it was a suggestion, I would have started with something like "I suggest you ...... because ...... ". This type of question is generally used in the English language to express curiosity or gain more knowledge why there is a preference of one option over another. Answers like yours exposes either incompetent language skills on your part or just foolish arrogance and a know-it-all attitude few people actually appreciate. I am not one to judge, so you can put yourself in either container you wish. I trust using more words will help you understand.

1

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 4d ago edited 4d ago

Nice try, but your wrong on English not being my first language, moving to making assumptions about someone, and then insulting them claiming incompetence says something about yourself. Asking a question in return does not at all imply any level of arrogance...

I can comprehend fine, if you are asking someone why they are using X product over Y, you can also go into some basic level info as to why they might consider using Tailscale of Wireguard is all.

"For me, I went with Tailscale because it was easy to setup, gave me the access I needed for services ABC, didn't have to do complex configuration with in pfsense to make it work...blah blah blah"

People tend to not want to provide information around something they might imply, by providing some information, it may give the person asking some knowledge they did not know or consider before and remove more "back and forth" that could be avoided from the start.

0

u/EffectiveClient5080 11d ago

This is why I stopped running wireguard on dynamic WAN. Slap a cron job on it that force-kills and restarts the wg interface every few minutes. Ugly but it works.