pfSense Wireguard Site-to-Site VPN Setup (3-Way) Tutorial

Поділитися
Вставка
  • Опубліковано 27 вер 2024

КОМЕНТАРІ • 48

  • @Paulser1991
    @Paulser1991 9 місяців тому +1

    Not sure if this just me but I had better experance also setting the MTU on wireguard interfaces (All Sites) as pfsense wireguard seems fussy from time to time about this. E.g. 1280 (or maybe somthing higher)

    • @sheridans
      @sheridans  8 місяців тому

      I have had issues with this before, my home instance, for example, has both MTU and MSS set to 1420 and hasn't had any issues at all. During testing for this video, it didn't seem to make a difference.

  • @RoboNuggie
    @RoboNuggie 10 місяців тому +1

    This is gold... I'm going to bookmark this, and use it as a reference guide....
    Top stuff Sam!

  • @trevelvin7455
    @trevelvin7455 10 місяців тому +1

    Enjoyed this video. Have seen other pfsense wireguard site to site videos but enjoyed this one as you added a third one, which a lot of people would do later..thanks

    • @sheridans
      @sheridans  10 місяців тому

      Thank you for the kind words, and taking the time to leave feedback
      Much appreciated 🙏

  • @eostrike
    @eostrike 9 місяців тому +1

    Thank you for making this video, we'll done.

    • @sheridans
      @sheridans  9 місяців тому +1

      Thanks for the feedback 👍

  • @bopal93
    @bopal93 9 місяців тому +1

    Great video. Always love your explanations

    • @sheridans
      @sheridans  9 місяців тому

      Thank you for the kind words

  • @paulturner968
    @paulturner968 10 місяців тому +1

    Outstanding! I finally got my third location added. Thank You!! My only wish is that it would have just gone a bit further and got SiteB & SiteC talking. You mentioned firewall rules and am messing with it but not having success. However, appreciative of the help you provided.

    • @sheridans
      @sheridans  10 місяців тому

      Glad you got it working, I may take a look at getting site b and c talking, it's not something I've needed tbh, as long as everything coupd speak back to main sites that's all i required

    • @paulturner968
      @paulturner968 10 місяців тому +2

      @@sheridans Thank you for your response! Ya, I travel between the three offices quite a bit. I have heard about a 'mesh' solution vs 'hub and spoke', but very hard to find any content on. You might get a lot of views ;)

  • @MohammedRadwan-j9u
    @MohammedRadwan-j9u 4 місяці тому +1

    Thank you. great video. I wish this was a mesh setup to provide some redundancy between the three sites as there's almost no content or tutorials on this anywhere on the web.
    Please think of making a video for a WG mesh setup between 3 sites.
    Also you've earned a new sub! 👍⭐

    • @sheridans
      @sheridans  4 місяці тому

      Thank you for the sub. You're not the first person yo mention this, will look at covering it

  • @GpconnectInfohotspot
    @GpconnectInfohotspot 7 днів тому

    what about pfsense just being a client by initiating the connection to a remote server ?

  • @HuseynBaxshiyev
    @HuseynBaxshiyev 7 місяців тому +1

    Thanks !

  • @KingBondTang
    @KingBondTang 6 місяців тому +1

    could do opnsense site 2 site tutorial on wireguard please

    • @sheridans
      @sheridans  6 місяців тому +1

      Yeah, can't see why not. Will try to fit it in within next week or two

    • @KingBondTang
      @KingBondTang 5 місяців тому

      Thank you @@sheridans

  • @geepriest
    @geepriest 10 місяців тому +1

    Excellent tutorial Sir... is it possible to access network devices via hostname and not just via IP address?

    • @sheridans
      @sheridans  10 місяців тому +1

      You can do it in pfsense via dns resolver, tell it to send all requests for youdomain.local for example to a server than can resolver them (ie dc)

    • @sheridans
      @sheridans  7 місяців тому

      Hi, sorry for replying late. youtube comments are hard to spot at best. yes, you can point to a dns server or edit static hosts file.

  • @kevinbradt835
    @kevinbradt835 5 місяців тому

    sheridan computers i folowed your video step for step and it does not work at all

  • @walpicarbrasil
    @walpicarbrasil 8 місяців тому +1

    Hello, the video is very good, but how do I make the link highly available? I made 2 tunnels and 2 separate pears, to create HA, but the routes only accept one with the same destination, I made automatic routes with OSFP following the DOC, but it didn't work, what would it look like in this case? Could you help me, please?

    • @sheridans
      @sheridans  8 місяців тому +1

      Thanks for the feedback, appreciated. I'd have to this in all honesty, out of curiosity will try to test this out

  • @sydplace1540
    @sydplace1540 7 місяців тому

    Hi, can you also please show the physical connection of two different machines. Thanks in advance.

    • @sheridans
      @sheridans  7 місяців тому

      What do you mean by physical connection? Sorry I don't understand

  • @Fidayan01
    @Fidayan01 10 місяців тому +1

    Hey Sir I wanted to ask you few things about asterisk can you help please 🥺

    • @sheridans
      @sheridans  10 місяців тому

      There's a link to our forum in the video description if you want to take it there

  • @peterdee1900
    @peterdee1900 3 місяці тому

    I have followed this guide, but clients behine each pfsense firewall can access the subnet of the otherside. What rules are needed to allow clients to talk to each other.

    • @sheridans
      @sheridans  3 місяці тому

      Have you tried disabling windows firewall on a machine you're trying to access as a test to make sure it's not firewall related?

    • @peterdee1900
      @peterdee1900 2 місяці тому +1

      @@sheridans I reboot sorted this issue out. Routes where correctly then pushed to the client computers.
      Thanks!

    • @sheridans
      @sheridans  2 місяці тому

      @@peterdee1900 Glad you got it working and thank you for the update regarding the reboot

  • @Hi5ist
    @Hi5ist 7 місяців тому

    Great video!
    Still having something wrong... If I test with ping in the pfsense diagnostic tool it works perfect, but it doesn't work if i do ping from y pc, I do research with no success, do yo have some clue?

    • @sheridans
      @sheridans  7 місяців тому

      Have you set the the allowedip setting?

    • @Hi5ist
      @Hi5ist 7 місяців тому

      @@sheridans Yes, I allowed the wireguard network and my remote site network, the problem is when I try to ping or connect from my Bridge interface as i had one to have 3 ports as a switch in my pfsense box

  • @aytacdede81
    @aytacdede81 8 місяців тому

    thanks for your video .
    i would like to ask something in my scheme ; i have 5 sites and each one conected between them using ipsec (site A has a server) so sometimes site A lost internet connection , so i put a new ethernet interface to my site a pfsense but my second internet conection in site A Pfsense coming from a Nat so i cant open port or like something because it is a home user internet . what i want to do : if site a internet down i want to use wireguard vpn to connect all other sites to site A using my second internet connection on it . otherwise ipsec vpn with my first static ip conection ip also working (sorry for my poor english) thanks for your answer

    • @aytacdede81
      @aytacdede81 8 місяців тому

      i tried to make with openvpn (i installed open vpn cliect to my server then these cliect conecting to my other sites pfsense openvpn server ) but open vpn is not stable and sometimes windows rdp stay with black screen i dont know reason but with ipsec everthing work perfectly .
      In summary, what I want to do is the following when the main internet of my site A fails to use my dynamic home internet double nat that makes connections using wireguard vpn.
      I don't think wireguard and pfsense would work pointing to the same lan?

    • @sheridans
      @sheridans  8 місяців тому +1

      OpenVPN is stable, it's more than likely external factors affecting it

    • @aytacdede81
      @aytacdede81 8 місяців тому

      ​@@sheridansfor example?

  • @Wora-dg9hw
    @Wora-dg9hw 8 місяців тому

    Do you have a way for adding other public IP addresses to utilize as backup links when the first one fails at the server site? Thank you in advance.

  • @allaboutcomputernetworks
    @allaboutcomputernetworks 6 місяців тому +1

    Nice tutorial video.👍

    • @sheridans
      @sheridans  6 місяців тому

      Thank you for the kind words, always appreciated to see someone is finding some use out of them 😊

  • @rudypieplenbosch6752
    @rudypieplenbosch6752 10 місяців тому +1

    More interested in site to site with Zerotier.

    • @sheridans
      @sheridans  10 місяців тому

      I'll see what I can do :)

    • @rudypieplenbosch6752
      @rudypieplenbosch6752 10 місяців тому +1

      @@sheridans Really, wow thanks for considering