Site Tools


vpn-wireguard

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
vpn-wireguard [2025/11/12 19:56] – [Introduction] -Reorder sentence about Set up WireGuard HOWTO hogwildvpn-wireguard [2025/11/19 20:30] (current) – [Problem: Traffic flowing in one Direction] -Change to: " hogwild
Line 101: Line 101:
 **Poll Interval** - a watchdog timer for the WireGuard connection (in minutes) **Poll Interval** - a watchdog timer for the WireGuard connection (in minutes)
  
-If we can'ping 1.1.1.1 via the WireGuard interface, wg is restarted.\\  \\ FIXME +This causes FreshTomato to ping 1.1.1.1 via the WireGuard interface. If no reply is received in timethe wg service is restarted.\\  \\
- +
-  * The recommended setting is 25 seconds. This causes WireGuard \\ to send a small packet to its peer every 25 seconds when no \\ other traffic occurs. This keeps the connection alive through \\ NAT or firewalls that might otherwise close idle UDP sessions. \\ \\  +
-  * Default: 0. This disables the feature, so packets are sent only\\ as needed. This is fine for most users not behind restrictive NAT.+
  
  \\  \\
Line 484: Line 481:
     * Remote LAN IP     * Remote LAN IP
  
- \\  The point of failure you find will provide critical insight into the type of issue you are facing.+ \\  The point of failure you find will guide you in understanding what type of issue you are facing.
  
  \\  \\
 +
 +
 +==== Problem: Traffic flowing in only one Direction ====
  
  \\  \\
 +
 +Sometimes, it may occur that from one end of your setup ("A)", you can ping devices and both VPN virtual interfaces at the other end ("B"), however, from end B, you cannot ping the remote router or devices or the client VPN virtual interface at end A.
 +
 +It this occurs, please check that there are default routes setup from B to A. Also, please check that on the client side, (in this case, end B), the "Inbound firewall" option is disabled. On the server side, make sure to add the client's subnet, so it knows how to route traffic from the server back to the client.
  
  
vpn-wireguard.1762977388.txt.gz · Last modified: by hogwild