Weird Wireguard issues I could use some help with.
Weird Wireguard issues I could use some help with.
I've hit a wall with a weird Wireguard issue. I'm trying to connect my phone (over cell) to my home router using wireguard and it will not connect.
- The keys are all correct.
- The IPs are all correct.
- The ports are open on the firewall.
- My router has a public IP, no CGNAT.
The router is opnsense, I have a tcpdump session going and when I attempt a connection from the phone I see 0 packets on that port. I am able to ping the router and reach the web server sitting behind it from the phone.
I have a VPS that I configured WG on and the phone connects fine to that. I also tested configuring the VPS to connect to my home router and that also works fine.
I'm really at a loss as to where to go next.
Edit 2: I completely blew out the config on both sides and rebuilt it from scratch, using a different UDP port, and it all appears to be working now. Thanks for everyone's help in tracking this down.
Edit: It was requested I provide my configs.
opnsense:
#################################################### # Interface settings, not used by `wg` # # Only used for reference and detection of changes # # in the configuration # #################################################### # Address = 172.31.254.1/24 # DNS = # MTU = # disableroutes = 0 # gateway = [Interface] PrivateKey = ListenPort = 51821 [Peer] # friendly_name = note20 PublicKey = AllowedIPs = 172.31.254.100/32
Android:
[Interface] Address = 172.31.254.100/32 PrivateKey = [Peer] AllowedIPs = 0.0.0.0/32 Endpoint = :51821 PublicKey =
The allowed IP's for your peer should be 0.0.0.0/0 NOT /32. (That literally means that only IP 0.0.0.0 is allowed). I'm pretty sure that's your problem since 0.0.0.0 is not a valid IP that anyone is assigned.
Well, that was a silly mistake. Thanks for noticing it. I rebuilt the client side several times yesterday, so I can't say for certain I made that typo each time, but it's possible.
I just blew out the whole thing, both sides, and rebuilt it from scratch using a different UDP port and it's all working now.