Wireguard - Can connect, but can't do anything

Comments

10 comments

  • Avatar
    Firewalla

    Are you VPN from outside to inside? or from inside to inside?

    If you are VPN from outside to inside, can you check if your phone (wireguard client) IP is not the same as your home network?

    0
    Comment actions Permalink
  • Avatar
    Dr. P. Venkman

    Thanks much for the reply.

    I'm outside the network (I'm at my office, and on my iPhone, I'm using my cell phone carrier's connection, not WiFi). The IP address my phone gets from Verizon and the IP address my desktop gets from my office network are both definitely in different ranges than my home network (all VLAN subnets, including the Wireguard VPN subnet).

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Make sure you are not sharing wireguard profiles, otherwise it won't work. Does your PC/MAC work with a different wireguard profile?

    0
    Comment actions Permalink
  • Avatar
    Dr. P. Venkman

    I configured a profile for each (though I wasn't ever connected with both at the same time, anyway). After it didn't work, I wiped away the VPN server setup and all clients in the FWG and did it again - same result.

    • On the iPhone, I saved the config file to the phone's file storage, then imported it into the Wireguard app. It connects, no problem (and the FWG says it connected). But then if I browse the internet, I'm still using the Verizon connection.
    • On the PC, I downloaded the Windows client and created a tunnel from the config file. It connects, but once it does, I can't get to the internet at all from the computer, and I can't ping or access anything on the network behind the FWG. IPconfig tells me I've got an IP address in the FWG's wireguard network range (but oddly, it tells me the default gateway is 0.0.0.0).
    1
    Comment actions Permalink
  • Avatar
    Firewalla

    I just created a ticket for you, will get a developer to look 

    0
    Comment actions Permalink
  • Avatar
    beachdog

    @dr. P. Venkman 

    How did this get resolved? Similar to you,  I tried setting up vpn server on my FWB+ and Android phone. With WiFi on the phone off, I get the confirmation of the wire guard connection but can't access any of the devices as if I'm home on the WiFi. 

     

     

    0
    Comment actions Permalink
  • Avatar
    Ilias Leontiadis

    I am also wondering what was the solution. I can also connect to my WireGuard server (running on a Firewalla purple) from my iPad but no traffic goes through.

    On my iPad I get an IP, I can see on the firewall web interface that there is one device connected. Also the vpn client is configured to allow 0.0.0.0/0

    0
    Comment actions Permalink
  • Avatar
    Dr. P. Venkman

    I hate to be unhelpful, but I didn’t do anything. They opened a ticket for me, and by the time I got to the ticket, a few hours had passed. I tried again, and it was working fine. I’m not sure if there is some amount of time needed for the firewalla to update/provision VPN settings that I wasn’t allowing for, but after a break, it just started working.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    WireGuard is a connectionless protocol. So it will always "connect" regardless if there is a "connection" or not. So if you are not connecting, it is highly likely you may not be able to reach the server. (if this happens, try another wifi or turn to LTE)

    If you have tested the server and it works from other external wifi, then the problem is highly likely that your current ISP/WiFi may be blocking VPN/wireguard. If you never tested wireguard before, you will need go and tap on VPN server and check and make sure wireguard is fully up

    0
    Comment actions Permalink
  • Avatar
    MattT

    If you've changed your IP Address range in the Wireguard Network settings after you've shared your device profiles, you have to re-issue your profiles to each device as otherwise whilst they will get a new IP, they will be looking at the wrong DNS server. 

    1
    Comment actions Permalink

Please sign in to leave a comment.