You are not logged in.

#1 2020-03-08 16:11:57

brando56894
Member
From: NYC
Registered: 2008-08-03
Posts: 681

Can't Connect To Anything Behind Wireguard

So I managed to get a wireguard connection established (the first time around this time, from work nonetheless, there must've been big changes in the past 2 months), but I can't manage to hit anything past my router, and I can't figure out why. The "server" is running Arch (wireguard-tools v1.0.20200206) and the "client" is running OS X 10.14.6 (wireguard-tools v1.0.20200206).

Server info

 [root@wireguard wireguard]$ sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1

 [root@wireguard wireguard]$ ip route show
default via 192.168.1.1 dev ens18 proto static
192.168.1.0/24 dev ens18 proto kernel scope link src 192.168.1.13
192.168.199.0/24 dev wg0 proto kernel scope link src 192.168.199.1

 [root@wireguard wireguard]$ wg show
interface: wg0
  public key: AmUv1a1SQhuN8S9CLoERWwltqxkJv30bCDXwsuutByk=
  private key: (hidden)
  listening port: 51871

peer: FNXMcfguJbOIqOuxpeBAypEQ5VgsxN0rXEUnSSE0ZkY=
  endpoint: publicIP:51902
  allowed ips: 192.168.199.2/32, 192.168.1.0/24
  latest handshake: 20 seconds ago
  transfer: 4.94 KiB received, 6.79 KiB sent
  persistent keepalive: every 25 seconds

 [root@wireguard wireguard]$ ping 192.168.199.2
PING 192.168.199.2 (192.168.199.2) 56(84) bytes of data.
64 bytes from 192.168.199.2: icmp_seq=1 ttl=64 time=19.1 ms
64 bytes from 192.168.199.2: icmp_seq=2 ttl=64 time=17.3 ms
64 bytes from 192.168.199.2: icmp_seq=3 ttl=64 time=17.0 ms
^C
--- 192.168.199.2 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 17.027/17.826/19.118/0.921 ms

I'm using a shell script to setup the interface, because if I use wg-quick /etc/wireguard/wg0.conf it will make the connection but won't allow me to ping 192.168.1.1 (my router)

 [root@wireguard wireguard]$ cat setup-interface.sh
#!/bin/bash

ip link add dev wg0 type wireguard
ip addr add 192.168.199.1/24 dev wg0
wg set wg0 listen-port 51871 private-key ./privatekey
wg set wg0 peer FNXMcfguJbOIqOuxpeBAypEQ5VgsxN0rXEUnSSE0ZkY= persistent-keepalive 25 allowed-ips 192.168.199.2/32,192.168.1.0/24 endpoint publicIP:51902
ip link set wg0 up

client info
I'm using the Wireguard app from the AppStore, here's the config file

[Interface]
PrivateKey = [redacted]
ListenPort = 51902
Address = 192.168.199.2/24
DNS = 192.168.199.1

[Peer]
PublicKey = AmUv1a1SQhuN8S9CLoERWwltqxkJv30bCDXwsuutByk=
AllowedIPs = 192.168.199.0/24
Endpoint =publicIP:51871
➜  ~ ping 192.168.1.7
PING 192.168.1.7 (192.168.1.7): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
^C
--- 192.168.1.7 ping statistics ---
3 packets transmitted, 0 packets received, 100.0% packet loss

➜  ~ ping 192.168.1.1
PING 192.168.1.1 (192.168.1.1): 56 data bytes
64 bytes from 192.168.1.1: icmp_seq=0 ttl=252 time=0.855 ms
64 bytes from 192.168.1.1: icmp_seq=1 ttl=252 time=0.896 ms
64 bytes from 192.168.1.1: icmp_seq=2 ttl=252 time=1.015 ms
^C
--- 192.168.1.1 ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 0.855/0.922/1.015/0.068 ms

➜  ~ ping 192.168.199.1
PING 192.168.199.1 (192.168.199.1): 56 data bytes
64 bytes from 192.168.199.1: icmp_seq=0 ttl=64 time=12.683 ms
64 bytes from 192.168.199.1: icmp_seq=1 ttl=64 time=12.752 ms
64 bytes from 192.168.199.1: icmp_seq=2 ttl=64 time=26.883 ms
^C
--- 192.168.199.1 ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 12.683/17.439/26.883/6.678 ms

OS X routes

➜  ~ netstat -nr|grep 192.168
192.168.0.1        utun1              UHS             0        0   utun1
192.168.1.0        utun1              UHS             0        0   utun1
192.168.199        link#23            UCS             1        0   utun1
192.168.199.1      link#23            UHWIi           1       57   utun1
192.168.199.2      192.168.199.2      UH              0        0   utun1

192.168.1.1 is my router in my apartment
192.168.1.7 is my server in my apartment
192.168.1.13 is the IP of the wireguard "server" which is running on 192.168.1.7

192.168.199.1 is the IP of the wireguard interface on the wireguard VM in my apartment
192.168.199.2 is the IP of the wireguard interface on the macbook at work

10.144.120.116 is the private IP of the macbook at work

What am I missing here?

Last edited by brando56894 (2020-03-08 16:16:29)

Offline

Board footer

Powered by FluxBB