You are here

Wireguard VPN (not for linking nodes together)

6 posts / 0 new
Last post
VA7NIC
VA7NIC's picture
Wireguard VPN (not for linking nodes together)
Has anyone been successful using Wireguard to create a VPN into a AREDNMESH network?  I'd like to be able to access the mesh and its resources from the outside world without having additional Arednmesh hardware with me.

I've tried various environments such as PIVPN and the Wireguard VPN setup with in an Unraid server and made them work outside of the Mesh, but once I try to put the server inside the mesh lan, and port forward through a outside facing node, I do not any connectivity. I've tried different ports, but nothing seems to make it go.

When you connect to what should be a properly configured setup, the wireguard client claims it has connected and the logging shows its attempting to send handshake initiation to peer then comes back perhaps 5 seconds later reporting Handshake for peer with the configured ip:port info did not complete after 5 seconds, retrying (try 2) and then repeats that sequence until you disconnect.

The client GUI will also show a total of data its transmitted but nothing is received.  A quick look on the server end shows the tunnel ip transmit value increasing like it is actually sending data back to the client.

I've disabled/removed any firewalls on the client, and the arednmesh node has an IP on the same lan as the client.

If anyone has gotten around this issue, I'd like to know how.  It would make remote work much easier.

Things to note:  the mesh node has the latest release (3.25.x) and the wireguard client is the latest from the Wireguard site.  PiVPN is the latest release as is the Unraid distro.  

I can answer any other questions if anyone has one.

Thanks
Nick - VA7NIC

 
KN9U
Tailscale
Have you tried to run tailscale?
73
Matthew KN9U
VA7NIC
VA7NIC's picture
Aredn/Wireguard/VPN (not tunnelling)
I have briefly looked at tailscale, but would really like to figure what is causing wireguard to not work.  It has to be something very simple.
Will investigate tailscale this afternoon.

Nick - VA7NIC
K6CCC
K6CCC's picture
I want to make sure I
I want to make sure I understand what you are trying to do.  Are you attempting to use a non-AREDN device as one end of an AREDN WireGuard tunnel, or are you trying to establish a WG tunnel to some other device (completely outside of AREDN) and then have that device connect to a LAN port on an AREDN node in order to access the AREDN network.  From your description, I am assuming the first.  If that's the case, I would be surprised if that would work.  Even if you get the WG tunnel established, the AREDN node is expecting an AREDN node as a tunnel connected device, not a LAN device.
 
VA7NIC
VA7NIC's picture
I am trying to create a VPN
I am trying to create a VPN connection to a device on a mesh network,  but not an Aredn device.  The only part that touchs the Aredn hardware is the portforwarding from outside the mesh to the (in this test setup) raspberry pi connected on the mesh lan.

 
KN9U
Time
Also check the time on both ends, Wireguard need the time is be correct.
73
Matthew

Theme by Danetsoft and Danang Probo Sayekti inspired by Maksimer