I’ve hit a wall with a weird Wireguard issue. I’m trying to connect my phone (over cell) to my home router using wireguard and it will not connect.
- The keys are all correct.
- The IPs are all correct.
- The ports are open on the firewall.
- My router has a public IP, no CGNAT.
The router is opnsense, I have a tcpdump session going and when I attempt a connection from the phone I see 0 packets on that port. I am able to ping the router and reach the web server sitting behind it from the phone.
I have a VPS that I configured WG on and the phone connects fine to that. I also tested configuring the VPS to connect to my home router and that also works fine.
I’m really at a loss as to where to go next.
Edit 2: I completely blew out the config on both sides and rebuilt it from scratch, using a different UDP port, and it all appears to be working now. Thanks for everyone’s help in tracking this down.
Edit: It was requested I provide my configs.
opnsense:
####################################################
# Interface settings, not used by `wg` #
# Only used for reference and detection of changes #
# in the configuration #
####################################################
# Address = 172.31.254.1/24
# DNS =
# MTU =
# disableroutes = 0
# gateway =
[Interface]
PrivateKey =
ListenPort = 51821
[Peer]
# friendly_name = note20
PublicKey =
AllowedIPs = 172.31.254.100/32
Android:
[Interface]
Address = 172.31.254.100/32
PrivateKey =
[Peer]
AllowedIPs = 0.0.0.0/32
Endpoint = :51821
PublicKey =
This probably does not apply for you but don’t try sending wg over port 53, learned the hard way some routers simply won’t pass non-dns packets there.
Otherwise considering you are able to access VPS stuff from phone but not the router connected to the same VPS then I would checkif forwarding is enabled on the vpsif you can’t see any packets on the router side then it sounds like a routing issue at the vpsE: I am too baked and assumed you are trying to have the VPS as a central hop point.
My backup plan is to route the traffic through the VPS to the home network. I was hoping to avoid that hop.