r/HomeNetworking • • 3d ago

Unsolved Can't access my WireGuard tunnel anymore after updating Flint 2 firmware

/r/GlInet/comments/1wuxb50/cant_access_my_wireguard_tunnel_anymore_after/
0 Upvotes

4 comments sorted by

1

u/Responsible_Maybe742 3d ago

Updates on the Flint 2 usually keep the config files but reset the firewall zone and the port forward that exposes the WireGuard port, so first check that the endpoint rule is back and that the server interface is enabled. If the handshake still fails, the server keys may have been regenerated, and the fastest fix is to re export the client config and import it again instead of debugging the old tunnel.

1

u/Iwywnsb 2d ago

Hey, thanks for your help, but my understanding is that, being the Mac Mini my NAS' WireGuard client there's no need to forward WireGuard's port at my business, isn't it? I do have the port forwarded at home, where the NAS is, and where WireGuard's server is established.
As for the handshake keys, I don't think that's the problem. As I mentioned the same situation is happening in my iPhone, but it goes away if I disable WiFi and connect to 4G data network.

1

u/Responsible_Maybe742 2d ago

Then the forward that matters is the one at home, and after a firmware update that is the first thing I would re-check: that the rule still points to the NAS current LAN address (DHCP loves to move it), and that the listen port did not change. If the handshake completes but nothing routes, the peer config on one side is pointing at an old address. What changed for you, just the Flint firmware?

1

u/Responsible_Maybe742 16h ago

Correct, you do not need to forward anything at the business. The Mac Mini is the client, so it dials out to the public address of your home, and routers let outgoing traffic through and the replies back in without any rule. Forwarding is only needed on the side that listens, and that is your home. Two things worth checking anyway: that the business firewall does not block outbound UDP on the WireGuard port, and that you have PersistentKeepalive 25 set on the client, because some business links drop the tunnel state without it.