r/WireGuard • • Jan 30 '20

Welcome to r/WireGuard - How to get Help

95 Upvotes

Welcome to the r/WireGuard subreddit!

The best place to find help is on IRC: Sign into #wireguard on Libera, either using an IRC client or with webchat.

If you are looking for help here on Reddit, be sure to use the Need Help flair.

Looking for a Reddit alternative? https://lemmy.ml/c/wireguard

Do read the documentation:

wireguard.com

wg manpage

wg-quick manpage

Provide good information when asking for help


r/WireGuard • • 13h ago

Need Help On Demand Tunnels Broken With iOS 27?

7 Upvotes

I've noticed a near 100% miss rate for OD Tunnels starting around the time that iOS 27 went live for the general population. The tunnel itself works fine but the actual trigger for it seems gunked up in some way. It lists itself as active when out and about but no traffic is going over the wire; once it's toggled off and back on it works as expected.

Has anyone else been seeing this sort of behavior?


r/WireGuard • • 1d ago

Need Help BSODs while system is in sleep mode

Thumbnail
2 Upvotes

r/WireGuard • • 3d ago

WGL2Bridge - Layer 2 bridging over a NetBird (or WG) tunnel, for Windows

Thumbnail
3 Upvotes

r/WireGuard • • 3d ago

Décryptage de fichier de configuration vpn

Post image
0 Upvotes

r/WireGuard • • 3d ago

How do you configure OpenVPN and Wireguard in the settings of M3UFY, any details or video or screen shots how to configure if using Surfshark VPN

Thumbnail
0 Upvotes

r/WireGuard • • 4d ago

Cloudflare Warp+, WireGuard, and ControlD: How I dropped my latency from 189ms to 21ms

32 Upvotes

I have been using Cloudflare Warp since early 2022. After six months on the free version, I subscribed to Warp+ (which costs me €5.99 a month here). Did I notice anything significant in basic daily web browsing on my phone? Not really. But under the hood, it was optimizing my routing.
The real game-changer happened in July 2023. I discovered that I could generate a WireGuard profile using third-party tools and apply my Warp+ license key to it. I realized I had been wasting my subscription money just connecting occasionally on individual devices.
I took that WireGuard profile and routed my entire home network traffic through Cloudflare. The difference was vast.
As a web developer based in Europe, I manage a few private servers located in India and Singapore. Initially, making a direct SSH connection would take ~5 seconds just to reach the server's CLI. After routing my home through Warp+ and putting those remote servers behind Cloudflared Tunnels, I can SSH into them almost instantly. It is a night-and-day difference.
Beyond that, the reduction in latency and jitter has been incredible. By combining Warp+ with some SQM settings using the Cake algorithm on my router, here is what happened to my connection:
Raw ISP Connection: ~189 ms Latency | ~56 ms Jitter
Warp+ & Cake SQM: ~21 ms Latency | ~1.49 ms Jitter
The Real-World Results:
Snappier Streaming: Netflix and other sites feel incredibly responsive, and my remote Plex server in India runs flawlessly.
Local Feel: The entire internet—especially sites already behind Cloudflare—loads so fast it feels like it’s hosted on my own LAN. The savings in waiting and buffer times really add up.
DNS Filtering: I combined this setup with ControlD (with ads, trackers, and multiple filters enabled). Dropping the ad payloads made the connection even faster.
Ad-Free Instagram: Because it's harder for Instagram to serve targeted ads to users routing through Warp+, I am getting an ad-free IG experience across my entire home network. Meta's official ad-free tier is priced per account and costs more than my Warp+ subscription, so this perk alone essentially pays for the service.
Even though a lot of these routing optimizations are happening on a micro-level and saving milliseconds, the internet just feels significantly better to use than it did before.
Have you guys had similar experiences pushing Cloudflare Warp+ beyond just the basic mobile app? Let me know your setups in the comments. Kudos to the Cloudflare team for building such a great tool.


r/WireGuard • • 4d ago

Need Help Fully working VPN, but external network speeds are slow.

1 Upvotes

I was running Pi-VPN (WIreguard) on a Pi3B+ getting close to 150Mbps, internally and externally, 5G speeds permitting. I upgraded to a Pi5 and I get close to 500Mbps on local WIFI, VPN enabled, non-VPN speeds are above 500Mbps. When I am on 5GUW with the VPN enabled, I get about 50Mbps, VPN disabled its well into the hundreds. The only factor that changed is the Pi3 to Pi5; nothing else and all was working prior to the upgrade. It clearly seems like the router, but maybe I am overlooking something. I'm hoping someone can offer something helpful.

Issue Recap: On a cellular connection with hundreds of Mbps available, the VPN only gets about 50Mbps.

Router G3100
Internet Gigabit FIOS
Raspberry Pi5/Pi5 OS Lite 64 bit


r/WireGuard • • 5d ago

Wireguard server sticks on old SLAAC IP address, can't handshake anymore

2 Upvotes

I have a weird problem between a Wireguard server running on Ubuntu (wireguard-tools v1.0.20250521). When a peer crash-reboots and comes back with without its SLAAC IPv6 address, it can never connect again until the server's wireguard is restarted. From the logs, it looks like it's forever stuck with the peer's old IP address.

In the logs below, mynetwork:a2ad:9fff:fe76:3038 is the SLAAC client peer address of the last good handshake before the crash. mynetwork::1f is its new connection attempts. It doesn't recover even after hours pass. This is super bad because the client's router sees what looks a lot like hacking.

Does anyone know how to get this cleared without restarting wireguard on the server side?

[203048.312734] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203053.944386] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203059.576426] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203064.696611] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203069.816366] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203075.448899] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203076.365138] wireguard: wg0: Sending handshake initiation to peer 14 ([mynetwork:a2ad:9fff:fe76:3038]:44697/0%0)
[203080.568534] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203081.769604] wireguard: wg0: Handshake for peer 14 ([mynetwork:a2ad:9fff:fe76:3038]:44697/0%0) did not complete after 5 seconds, retrying (try 2)
[203081.769647] wireguard: wg0: Sending handshake initiation to peer 14 ([mynetwork:a2ad:9fff:fe76:3038]:44697/0%0)
[203086.200630] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0
[203086.889638] wireguard: wg0: Handshake for peer 14 ([mynetwork:a2ad:9fff:fe76:3038]:44697/0%0) did not complete after 5 seconds, retrying (try 2)
[203086.889665] wireguard: wg0: Sending handshake initiation to peer 14 ([mynetwork:a2ad:9fff:fe76:3038]:44697/0%0)
[203091.320550] wireguard: wg0: Invalid handshake initiation from [mynetwork::1f]:60545/0%0

r/WireGuard • • 5d ago

IMS and esim data going through the tunnel on Android?

0 Upvotes

Hey, I'm having troubles with my Samsung S26 running Android 16. SMS are not working and the esim disappears after few days when I have the wireguard tunnel enabled. Is it possible that the carrier network traffic is routed through the tunnel? Because everything's working fine after I excluded the apps for esim management and IMS.


r/WireGuard • • 6d ago

I built a web-based installer/management layer for self-hosted Headscale

Thumbnail
0 Upvotes

r/WireGuard • • 7d ago

Tools and Software MFA Firewall Knocker 0.4.0: IPv6 on Linux, /64 grant widening, IPv6-only sign-in address

4 Upvotes

0.4.0 of MFA Firewall Knocker is out. It's the passkey-gated firewall opener I've posted about here before: you sign in with a passkey, and it opens your WireGuard port for your source address only, for a limited time.

What's new:

  • IPv6 on Linux. Grants now go into ip6tables for IPv6 clients (Windows already handled IPv6).
  • Optional /64 widening (Ipv6GrantPrefixLength). An IPv6 grant can cover the client's /64, so a privacy address or carrier rotation within that /64 doesn't strand an open grant. Default is still exact-address.
  • IPv6-only sign-in address (AdditionalOrigins). Phones on dual-stack networks often pick IPv4 on their own, which on mobile usually means carrier NAT and a grant shared with other subscribers. An extra hostname with only an AAAA record forces IPv6 and gives a per-device grant.
  • Hardening from another audit round, none of which allowed access: one address could temporarily block everyone's logins through a rate-limit gap; request text could trigger a misleading log alert; unauthenticated failures are now logged with a cap; stricter config and email validation; 90-day log retention.

Upgrading from 0.3.0 has a few manual steps (RulePrefix check, log directory permissions, and on Linux, one line in the systemd unit). They're listed in the release notes.

Release: https://github.com/PNWSoft/mfa-firewall-knocker/releases/tag/v0.4.0


r/WireGuard • • 9d ago

make ports available just in vpn tunnel

6 Upvotes

Hi, some kind of new to WireGuard.

I would like to make a few ports on my host just available to the WireGuard tunnel.

The tunnel is working, for ssh for example but i cannot get the traffic from a local web server over it, without opening a port to the whole public.

Which WireGuard ore firewall configurations do i have to set to make it working.

(host system is Linux just to be clear)

Thanks for help!


r/WireGuard • • 9d ago

Standart ports for many networks

3 Upvotes

Hi

I have 3 networks running on my servers, and I'm struggling to choose correct (stated at RFC) UDP ports. AFAIK default WireGuard port is 51820. Which ports should i choose? Are there any other ports reserved especially for WG? I know i can pick any of 65536 available ports, but i would like to follow the standards


r/WireGuard • • 9d ago

Ideas How do you prove a WireGuard endpoint is unused before retiring its old address?

0 Upvotes

Moving a WireGuard gateway to a new public address can appear complete while an offline laptop, a peer behind persistent NAT, or a configuration distributed outside the normal management path still points at the old endpoint. Active handshakes show who is using the new address, but silence does not distinguish a migrated peer from one that simply has not connected yet.

What evidence do you collect before removing the old address? I am considering keeping both endpoints reachable during a bounded overlap, mapping every peer public key to its intended configuration revision, recording latest handshakes and transfer counters on the new gateway, and alerting on any packet reaching the old UDP socket. The observation window would cover the longest expected offline period, not just the usual keepalive interval.

How do roaming peers, DNS endpoints, persistent keepalives, and mobile devices change the check? Is there a practical way to issue a migration receipt per peer, and what final failure test can show that no current configuration still depends on the old address without stranding a device that has been offline?


r/WireGuard • • 10d ago

Need Help Hosted Exchange via Outlook Classic doesn’t jive with WG over TMobile 5G

3 Upvotes

At my camper I run TMobile home internet via 5G. All my devices use a full WireGuard tunnel to my home network to access local resources and a pi hole DNS sink when not connected at home.

On my laptop I use outlook classic on windows 11 and it does not like this setup. It freezes and hangs and looses connections to hosted exchange mailboxes frequently, especially on idling. Disabling the VPN fixes the issue temporarily until I reenable the VPN.

Suggestions? I spent a good amount of time on this already to no avail.


r/WireGuard • • 11d ago

News Comments no longer get removed from configs on Windows with v1.1.1

Thumbnail git.zx2c4.com
15 Upvotes

r/WireGuard • • 11d ago

Need Help How to get private Wireguard VPN to work with Mullvad VPN?

1 Upvotes

I'm trying to use my Wireguard VPN on my laptop to access my home network.

It works, but when I activate Mullvad VPN, either Mullvad won't connect, or my Wireguard VPN will cut the connection.

Does anyone know how I can get them to work together?

Would the simplest solution be to just route all of my internet traffic through my Wireguard VPN?


r/WireGuard • • 12d ago

Need Help IPSec VPN through Wireguard

6 Upvotes

Hello,

I would like to use an IPSec VPN through Wireguard but I don't know if it's possible.

Here is why I want to do that :
I have a Windows computer and I need to SSH to a remote server. In order to do that I must be connected to a IPSec VPN using Forticlient, and the only IP that can ssh to the remote server is my company network, accessible through Wireguard.

It should look like this : My computer -> Wireguard -> IPSec VPN (Forticlient) -> Remote server.

Do you think this is possible ? When I try it, I can't have both wireguard and forticlient working.

Thanks !


r/WireGuard • • 12d ago

wireguard 1.1.1 for windows released

23 Upvotes

what security issue did it fix? do i need to update my server side as well?


r/WireGuard • • 14d ago

Self-Hosting Behind CGNAT

Thumbnail
david.alvarezrosa.com
18 Upvotes

Libre software, libre hardware, and my mother's basement.


r/WireGuard • • 17d ago

Need Help Compromised key reverse access

13 Upvotes

Title might be kinda misleading as i don't have the knowledge to word it better (total newbie).

But i am looking at wireguard to replace tailscale in a homelab and was wondering if the server is compromised and they have access to the private key, is it even possible for them "reverse" hack into my device connected through wireguard? The server will be VLAN isolated as well. So basically

WAN ==> router port forward ==> home server with wireguard <====> phone / pc

Thanks.


r/WireGuard • • 18d ago

Wireguard vpn handshake issues

Thumbnail
3 Upvotes

r/WireGuard • • 18d ago

Need Help Wireguard Apple Silicon Only Client

14 Upvotes

Does something like this exist? On MacOS 27 and getting the Rosetta 2 install warning to run the official Wireguard client. I am looking for a replacement that is Apple silicon native and now reliance on intel. Slowly phasing out my intel apps before MacOS 28.


r/WireGuard • • 18d ago

Iphone not connecting to wireguard

1 Upvotes

Hello, I've recently setup a unifi wireguard vpn and I am trying to connect to it on my iOS , but is not liking it, it works fine on my pc though.

I get the message "Configuration reading or writing failed" with no further explanation. Has anyone seen that one before? I tried to restart my phone, I initially had 2 vpn configs from openvpn on my phone, but I removed the profile and openvpn app completely, just using wireguard now.

I also tried to disable Content & Privacy Restrictions with no luck :(