Development discussion of WireGuard
 help / color / mirror / Atom feed
* ERX wireguard assistance please
@ 2021-07-06 13:25 Simon McNair
  2021-08-08 23:37 ` Phillip McMahon
  0 siblings, 1 reply; 2+ messages in thread
From: Simon McNair @ 2021-07-06 13:25 UTC (permalink / raw)
  To: wireguard

Hi,
I've searched to try and find the solution to my issue but I'm no expert 
and I'm not entirely sure what to search for.  I would appreciate your 
help please.

In summary, If I connect to my LAN via local WiFi I successfully connect 
to wireguard:
interface: wg0
   public key: <removed>
   private key: (hidden)
   listening port: 12345

peer: <removed>
   endpoint: 192.168.100.102:50084
   allowed ips: 10.250.250.5/32
   latest handshake: Now
   transfer: 157.33 KiB received, 536.33 KiB sent
   persistent keepalive: every 25 seconds

However if I try and connect via a remote network it fails.  My DDNS is 
resolving correctly to the correct IP so I can only think that firewall 
rules or NAT is somehow causing the issue.  Has anyone come across this 
before please ?
I don't know how to monitor my WAN port 12345 for activity, I tried 
tcpdump -n -v -i wg0 to no real benefit.


The ERX is running v2.0.9-hotfix.2 and 
e50-v2-v1.0.20210606-v1.0.20210424.deb


High level the infrastructure is:

LAN: 192.168.100.0/24
wg ip : 10.250.250.1/24
listen port:12345
route-allowed-ips:true
peer allowed ip is : 10.250.250.5/32
Firewall policy WAN_LOCAL default action drop, rule 2 wireguard 
destination port 12345, protocol udp, action accept


I would appreciate any help you can provide. The aim is to be able to 
access resources in the 192.168.100.0/24 subnet using routed ip from the 
10.250.250.0/24 transit network.

My apologies if my syntax or understanding is flawed.

Regards

Simon



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: ERX wireguard assistance please
  2021-07-06 13:25 ERX wireguard assistance please Simon McNair
@ 2021-08-08 23:37 ` Phillip McMahon
  0 siblings, 0 replies; 2+ messages in thread
From: Phillip McMahon @ 2021-08-08 23:37 UTC (permalink / raw)
  To: Simon McNair; +Cc: wireguard

Hi Simon,

I think that query is more for the ubiquity support forum, as you're
almost certainly going to have to supply your config.boot file etc.
which is somewhat outside of the pure wg.

Regards,

Phill

On Mon, 9 Aug 2021 at 01:06, Simon McNair <simonmcnair@gmail.com> wrote:
>
> Hi,
> I've searched to try and find the solution to my issue but I'm no expert
> and I'm not entirely sure what to search for.  I would appreciate your
> help please.
>
> In summary, If I connect to my LAN via local WiFi I successfully connect
> to wireguard:
> interface: wg0
>    public key: <removed>
>    private key: (hidden)
>    listening port: 12345
>
> peer: <removed>
>    endpoint: 192.168.100.102:50084
>    allowed ips: 10.250.250.5/32
>    latest handshake: Now
>    transfer: 157.33 KiB received, 536.33 KiB sent
>    persistent keepalive: every 25 seconds
>
> However if I try and connect via a remote network it fails.  My DDNS is
> resolving correctly to the correct IP so I can only think that firewall
> rules or NAT is somehow causing the issue.  Has anyone come across this
> before please ?
> I don't know how to monitor my WAN port 12345 for activity, I tried
> tcpdump -n -v -i wg0 to no real benefit.
>
>
> The ERX is running v2.0.9-hotfix.2 and
> e50-v2-v1.0.20210606-v1.0.20210424.deb
>
>
> High level the infrastructure is:
>
> LAN: 192.168.100.0/24
> wg ip : 10.250.250.1/24
> listen port:12345
> route-allowed-ips:true
> peer allowed ip is : 10.250.250.5/32
> Firewall policy WAN_LOCAL default action drop, rule 2 wireguard
> destination port 12345, protocol udp, action accept
>
>
> I would appreciate any help you can provide. The aim is to be able to
> access resources in the 192.168.100.0/24 subnet using routed ip from the
> 10.250.250.0/24 transit network.
>
> My apologies if my syntax or understanding is flawed.
>
> Regards
>
> Simon
>
>


-- 
Phillip McMahon

https://flowcrypt.com/me/phillipmcmahon
https://keys.openpgp.org/vks/v1/by-fingerprint/EA0483D4C864AA7C10994BE6A11E70ADFDA60CF9

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2021-08-08 23:40 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-07-06 13:25 ERX wireguard assistance please Simon McNair
2021-08-08 23:37 ` Phillip McMahon

Development discussion of WireGuard

This inbox may be cloned and mirrored by anyone:

	git clone --mirror https://inbox.vuxu.org/wireguard/0 wireguard/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 wireguard wireguard/ https://inbox.vuxu.org/wireguard \
		wireguard@lists.zx2c4.com
	public-inbox-index wireguard

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://inbox.vuxu.org/vuxu.archive.wireguard


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git