WireGuard VPN Server Configuration

Follow

Comments

18 comments

  • Avatar
    Andy brown

    Anyone else having issues With WireGuard on the new release?
    To me it looks like it’s not resolving the DNS as I can’t connect to any site through the VPN.
    I’ve tried changing the DNS in the network section for WireGuard to an external DNS and still nothing. I’ve reset the config and downloaded the file again. This is on two different profiles..

    3
    Comment actions Permalink
  • Avatar
    Andy brown

    All sorted, complete delete including clients. Not sure what happened the first time.

    0
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    This is great. Thanks for implementing it.

    Can WireGuard and the OpenVPN solution coexist on the Firewalla?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Yes, OpenVPN and Wireguard can live together nicely.  

    0
    Comment actions Permalink
  • Avatar
    Sean Buckels

    Andy Brown, I was having the same issue. I had to edit the tunnel to set the firewalla box as an allowed ip.

    0
    Comment actions Permalink
  • Avatar
    Abel Gonzalez

    Hi.  I am having issues enabling wireguard.  I tried it as soon it was released without problems, but decided to the disabled it since i was using opvn.  Now, I am trying to reenable wireguard through the phone app and I get the error "Error setting firerouter config".

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Apparently Firewalla WireGuard Server now allows six profiles. 

    0
    Comment actions Permalink
  • Avatar
    Sriram Mantravadi

    I am having similar problems. wireguard VPN is getting activated without any issues but i am not able to access any site. I tried removing the client and VPN setup completely and also tried adding the Firewalla box IP to the tunnel but still no luck. Any pointers how to resolve? I've setup my Firewalla in `Router Mode` and Wifi Router at AP mode. Thus it doesn't have Port forwarding Option enabled.

    1
    Comment actions Permalink
  • Avatar
    Firewalla

    look at "port forwarding" and make sure it says "Complete".   If not, it is likely your main modem/router is not in bridge mode, or you do not have a public IP.  and that can be checked here. https://help.firewalla.com/hc/en-us/articles/360055686674-How-to-see-if-you-have-a-public-IP-address-

    0
    Comment actions Permalink
  • Avatar
    Sriram Mantravadi

    Thanks for quick response. Yes, My Wifi Router (Orbi) is in AP Mode (essentially Bridge), Firewalla Gold is in Router Mode. On Both OpenVPN and WireGuard I could see Manual Setup required. If i m not wrong, port forwarding needs to be completed at router level. Orbi in Bridge mode disables this feature (or allows all ports from router since its in bridge mode). I tried adding UDP port on Firewalla App --> Networking --> NAT Settings --> New Port Forwarding but that didn't help.

    0
    Comment actions Permalink
  • Avatar
    Sukumar Patel

    Did a speed test via Wireguard. My plan is of 250Mbps, and the Wifi I was on at friend's place was 150M. I got 100Mbps via Wireguard.

    0
    Comment actions Permalink
  • Avatar
    Phillip Purcell

    Do Firewalla’s support site to site VPN?

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    @phillip yes but I think OpenVPN only for now.

    0
    Comment actions Permalink
  • Avatar
    Keith S

    So I tried open vpn and Winguard. It's does work and I can browse internet. However I thought it would like connecting to my local network and would have the same protection as I was at home. Is this not the case? I did a test to block twitter.com and it still let me through. After disconnecting from vpn and connected to my local wifi, it started blocking again. Does firewalls not block with rules while on vpn?

    0
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    Works fine here. This is what I see from home ads blocked and Reddit blocked.

    Turn on my IPvanish VPN which effectively bypasses my FWG and acts as though I am away from home. Ads are back and Reddit works. FWG no longer filtering. 




     

    Activate WireGuard sending the traffic from IPvanish through the FWG and all the rules. 



     

     

    This shows WireGuard is sending all my traffic through the FWG and the rules are working. 

    @Keith S - can you share more details about what you are experiencing?

     

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    So I can only test OpenVPN because WireGuard doesn't play well with dual WAN yet. Here's what I'm finding right now: 

    1. I can access LAN devices when connected via OpenVPN from outside my network. 
    2. Regular blocks (e.g. BLOCK: Apple.com) works within the the LAN. Rules on devices are not recognized through VPN so only rules on the VPN connection apply. 
    0
    Comment actions Permalink
  • Avatar
    Keith S

    @Chris Hewitt. So basically I've setup and tried both wireguard and open vpn on the firewall. Then I downloaded my profiles and connected. So both vpn profiles are connected over 5g or LTE. I'm not on my local network. I have not tried to connect to my other clients on my local network but I wanted to try and see if visiting sites that I block would still be blocked. As Michael Bierman stated. I get the same result. As if I'm connected locally to my own network or wifi I get blocked sites within my rules. When I disconnect my local network and use 5g or LTE and connect to either vpn, I cN access internet and probably my local computers but I was specifically testing out my blocked sites and the Active Protect. So if I'm not getting blocked by my rules I have in place on vpn, then maybe I'm not being protected by Active protect either. Which is not useful

    0
    Comment actions Permalink
  • Avatar
    Steve

    Hi How many clients can connect parallely when using a purple?

    1
    Comment actions Permalink

Please sign in to leave a comment.