Hetzner Cloud OPNsense Wirguard S2S VPN ER8411

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Hetzner Cloud OPNsense Wirguard S2S VPN ER8411

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-16 05:50:25
Model: ER8411   OC300   TL-SG3452XP  
Hardware Version:
Firmware Version:

 

Hallo Zusammen,
ich möchte gerne Server in der Hetzner Cloud nutzen.
Jetzt haben ich in der Hetzner Cloud eine OPNsense Firewall installiert und mit ER8411 mittels S2S Wireguard VPN. Die Verbindung zur Hetzner Cloud ist da. Ich kann die Firewall sowie das Gateway aus meinem Heimnetz erreichen. Wenn ich jetzt einen weiteren Server installiere, kann ich diesen Server nicht erreichen. Weder per Ping noch per ssh. Habt Ihr eine Idee warum?  Hat jemand vielleicht mit dieser Kombination Erfahrungen?

 

 

Hello together,
I would like to use servers in the Hetzner Cloud.
Now I have installed an OPNsense firewall in the Hetzner Cloud and with ER8411 using S2S Wireguard VPN. The connection to the Hetzner Cloud is there. I can reach the firewall as well as the gateway from my home network. If I now install another server, I cannot reach this server. Neither by ping nor by ssh. Do you have any idea why?   

Does anyone have experience with this combination?

 

 

Information:

ER8411 v1.0 Firmware: 1.1.0
TL-SG3452XP v2.0 Firmware: 2.0.3
OC300 v1.0

Firmware: 1.19.3

Controller-Version: 5.12.9

172.x.x.x/16 Heimnetz
10.100.0.0/24

Hetzner LAN

10.100.1.0/24 WireGuard Transfernetz


OPNSense Route:

 

Danke / Thanks

 

  0      
  0      
#1
Options
5 Reply
Re:Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-17 01:49:11

Hi @Tpexe 

Thanks for posting in our business forum.

Would like to see more about your config and please mosaic your key or other sensitive info. Seem to be a config issue if you don't set up ACL to block it.

You can refer to the guide we had before Configuration Guide How to Configure Site-to-Site WireGuard VPN on Omada Controller

 

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-17 07:28:15

Hi @Clive_A,

 

thank you for your help.


I have no ACL configured for this case.
ACL was not used in the How To.

 

Attached the configuration

 

OC300:

 

 

 

OPNsense:

 

 

 

Firewall Rules:

Interface Wireguard: Any Any
Interface Hetzner network: Any Any

 

should anything be missing let me know.
Thanks for the support.

 

Thx

  0  
  0  
#3
Options
Re:Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-19 08:28:45 - last edited 2023-10-19 08:28:55

Hi @Tpexe 

Thanks for posting in our business forum.

Not sure if there is any problem with the opensense. Have you tried to modify your subnet? It does not match. I don't find anything wrong so far.

Is the tunnel up?

If you try to ping the gateway, possible?

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-19 08:35:15

Hi @Clive_A, 

 

thanks.

 

Yes the tunnel is active.
I can ping OPNsense and configure it with local IP (10.100.0.4).
I can also ping the gateway 10.100.0.1.

Then it stops, other servers do not work. I have an unconfigured Debian server installed in the cloud, I can't ping it.

 

Thx.

  0  
  0  
#5
Options
Re:Hetzner Cloud OPNsense Wirguard S2S VPN ER8411
2023-10-19 09:06:14

Hi @Tpexe 

Thanks for posting in our business forum.

Tpexe wrote

Hi @Clive_A, 

 

thanks.

 

Yes the tunnel is active.
I can ping OPNsense and configure it with local IP (10.100.0.4).
I can also ping the gateway 10.100.0.1.

Then it stops, other servers do not work. I have an unconfigured Debian server installed in the cloud, I can't ping it.

 

Thx.

If you can ping all the gateway IPs, but not the servers/IPs in your remote LAN, I think you should check the firewall-related stuff. When I test NAT traversal with Tailscale or other stuff, I am not able to access the internal devices too. I can access the router without any issue but not inside the LAN. But it should be accessible. Usually, it is the device blocks the requests.

 

WG is active based on your description and it performs well. Try disabling the firewall and other stuff.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#6
Options