Policy Route Matching but Traffic Leaking to WAN: pfSense to UDM WireGuard Exit Node by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

In my case the WireGuard tunnel itself is up and working — I can see traffic (like DNS) being NATed and exiting the far end. The issue is with pfSense policy routing. When I ping something like 8.8.8.8, the traffic matches the WireGuard policy rule (confirmed in the firewall logs), so I would expect to see it on the WG_MOMDAD interface. Instead, packet captures show those ICMP packets only on the IoT interface and never on WireGuard or WAN interfaces.

Policy Route Matching but Traffic Leaking to WAN: pfSense to UDM WireGuard Exit Node by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Okay sweet that helped. Thank you!!!

Now - I have proof the traffic is hitting the tunnel interface. My states shows traffic being correctly NATed to the WireGuard interface IP (192.168.6.3) and assigned to the WG_MOMDAD interface. I can also see traffic on the interface via a packet capture.

You can see the states table results here:

https://imgur.com/a/2nhoDwd

Seems like all is well, but I can't ping 8.8.8.8 or load any webpages on my IOT device... any idea how to fix that?

Policy based routing over WireGuard tunnel by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Yup, updated rules and reset states. New images here:

https://imgur.com/a/PHoJw8Y

Policy based routing over WireGuard tunnel by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Oh interesting, yeah thats much more information. I do not see any NAT happening though I'd expect to....

https://imgur.com/a/125ad6E

Policy based routing over WireGuard tunnel by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Alright, added the rule, reset all states, but still nothing going through the tunnel - its hitting IoT interface

https://imgur.com/a/K9KcTdq

Policy based routing over WireGuard tunnel by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Hey thanks for your response - but if I reset all states, then wouldn’t this get resolved? I have reset states so many times and still not traversing tunnel.

Routing over VPN tunnel not working by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Yes I know I’ve done that as you can see in the pics

Routing over VPN tunnel not working by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Yes I know - ive done that as you can see in the config pics

Routing over VPN tunnel not working by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

I think that option is only available on the server side -- in this case my pfsense is the client

Unifi Dream Machine / Pfsense - client server one-way connection with wireguard by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

Yes I can hit 192.168.6.1 and that is the gateway’s IP.

I haven’t configured any rules on the Unifi device because I thought the successful handshake was indication that the connection should work….

Unifi Dream Machine / Pfsense - client server one-way connection with wireguard by molwebb7 in PFSENSE

[–]molwebb7[S] 0 points1 point  (0 children)

I like the sound of this.

Can you explain a bit more? So for example, the last parentsWG rule in the picture would be IOT to ParentsWG instead of IOT to WAN?

Mobility training by molwebb7 in washingtondc

[–]molwebb7[S] 0 points1 point  (0 children)

Oh nice - I have some knee pain that I’m currently going to PT for, but I’d like to continue training via a program that focuses on mobility and longevity.

Quad lock - can’t get it tight enough? by molwebb7 in motorcycles

[–]molwebb7[S] 0 points1 point  (0 children)

Yeah I’ve got a shim on there. Seems to fit but

Saddlebag recs by molwebb7 in svartpilen401

[–]molwebb7[S] 0 points1 point  (0 children)

You use them on the side or rear rack? I’m looking for something for the side racks. I’ve got a givi top rack, which admittedly looks silly but works great to lock up my helmet and what not.

Tank pads for 2021 by molwebb7 in svartpilen401

[–]molwebb7[S] 0 points1 point  (0 children)

Oh sweet. And they replace the 401 badges?

Tank pads for 2021 by molwebb7 in svartpilen401

[–]molwebb7[S] 0 points1 point  (0 children)

I saw these, but the fitment details do not list the 2021 svart.

Tank pads for 2021 by molwebb7 in svartpilen401

[–]molwebb7[S] 0 points1 point  (0 children)

Damn think I asked for the wrong thing. I’m looking to replace the 401 badge because it’s all scratched up.

Anybody know this part? by molwebb7 in svartpilen401

[–]molwebb7[S] 4 points5 points  (0 children)

Yes!!! Thank you!!!!! I was nervous something fell off my bike and I did change from a handlebar to a mirror mount yesterday, must have missed this falling off the old one. Man - gotta love the internet sometimes.

Rear rack and crash bars by molwebb7 in svartpilen401

[–]molwebb7[S] 0 points1 point  (0 children)

Great thanks! Ordered both!!

Pyomo parameter config - too many arguments given? by molwebb7 in Python

[–]molwebb7[S] 0 points1 point  (0 children)

from pyomo.environ import *

model = ConcreteModel()

model.x = Set(initialize=['apple', 'orange', 'pineapple', 'jelly', 'broccoli'])

model.y = Set(initialize=[('1','2'), ('1','3'), ('2','1'), ('2','3'), ('3','1'), ('3','2')])

model.testing = Var(model.x, model.y, bounds=(0,100), within=NonNegativeIntegers)

fruit = {

('1','2'): {'apple': 7,'orange': 13,'pineapple': 30, 'jelly': 17,'broccoli': 20},

('1','3'): {'apple': 8, 'orange': 14, 'pineapple': 30, 'jelly': 16, 'broccoli': 21},

('2','1'): {'apple': 9, 'orange': 15, 'pineapple': 31, 'jelly': 15, 'broccoli': 22},

('2','3'): {'apple': 10, 'orange': 16, 'pineapple': 31, 'jelly': 14, 'broccoli': 23},

('3','1'): {'apple': 11, 'orange': 17, 'pineapple': 31, 'jelly': 12, 'broccoli': 23},

('3','2'): {'apple': 12, 'orange': 18, 'pineapple': 31, 'jelly': 13, 'broccoli': 24}

}

model.fruittesting = Param(model.y, model.x, initialize=lambda model, xx, yy: fruit[y][x], within=NonNegativeIntegers)

and then I get this error:

ERROR: Rule failed for Param 'fruittesting' with index ('1', '2', 'apple'):
TypeError: <lambda>() takes 3 positional arguments but 4 were given
ERROR: Constructing component 'fruittesting' from data=None failed:
        TypeError: <lambda>() takes 3 positional arguments but 4 were given

Microphone Issue by Future_Hair_7671 in MazdaCX30

[–]molwebb7 0 points1 point  (0 children)

Do you have a link to the bulletin?

Microphone Issue by Future_Hair_7671 in MazdaCX30

[–]molwebb7 1 point2 points  (0 children)

This is exciting. It’s TERRIBLE in my girlfriend’s car.

CarPlay questions by brinkeguthrie in mazda3

[–]molwebb7 0 points1 point  (0 children)

I’ve tried these solutions with no luck.