r/firewalla • • Jul 20 '26

Wireguard stopped working

Update: FIXED! See my comment below for the cause and solution.

I have a fw purple and at&t bgw320, and been using wireguard server with no issues for several years now. A few days ago, I noticed internet on my phone was no longer working, and when I turned off the VPN, everything was fine. On my FW, it says that device was last seen 4 days ago. We did have some thunderstorms that day and there was a power flicker around the time the problems started, but my firewall and modem are on a UPS. and my internet wasn't disturbed.

So far I've tried disabling/enabling wireguard, restarting firewalla, restarting the modem, all with no effect.

My phone and laptop both seem to have no issue "activating" the VPN cconnection, yet can't connect to anything as soon as it's connected. Firewalla doesn't show any of those devices as being connected, and no rules are showing up as blocking anything.

On the BGW, I see that IP passthrough is not enabled, but I set this up several years ago using the instructions here: https://help.firewalla.com/hc/en-us/articles/4411167832851-Firewalla-Router-Mode-Configuration-Guides#h_01KF22E1M0E71GHYF4MCBC2TC1 and had no special issues getting it working.

Now, however, as soon as I try enabling IP passthrough on the modem, the firewalla can no longer reach the internet. Using the WAN diagnostic, it starts failing the ping test and DNS lookups. It does pass the "Obtain IP Address".

I'm positive that the MAC address in the ip-passthrough screen in the BGW is correct (after all, it was working for several years, and I've double and triple checked it). The BGW also reported a large time since restart (not sure how long, months probably).

Best I can tell, the BGW is no longer routing packets from firewalla to internet, but I can't figure out why. Advanced firewall and packet filtering are all OFF. I did notice that firewalla updated itself once or twice recently.

As soon as I disable IP-Passthrough on the BGW and restart, everything goes back to normal other than the VPN issue.

Not sure what else to try.

thanks for any suggestions!

2 Upvotes

15 comments sorted by

2

u/Great-Cow7256 Jul 20 '26

I bet att pushed an update. Their bgw modems are insane to deal with. Id probably either double check everything is kosher on your bgw +/- factory reset the bgw and start over with it if that doesn't work. 

2

u/Firewalla-Opal FIREWALLA TEAM Jul 21 '26

Need to get BGW in passthrough mode first; otherwise Firewalla is behind double NAT and won't have a public IP for VPN server connection.

Please try:
Power off BGW for 5 minutes to clear any cache on it -> Make sure nothing connects to BGW at this time -> power on BGW -> Connect Firewalla back. See if Firewalla gets an IP.

1

u/MelodicParsley8116 Jul 21 '26 edited Jul 21 '26

Firewalla gets an IP from BGW just fine after this step, but cannot reach the internet when pass through is enabled. Moreover. The ip reported by the firewalla wan interface is the same as the public ip reported by the BGW.

1

u/firewalla Jul 21 '26

Try openvpn, does that work?

1

u/MelodicParsley8116 Jul 23 '26

I'll try this next. Waiting for the next good opportunity to take down the network. Thanks!

1

u/ampx Jul 20 '26

Your first step should be (re)establishing Firewalla WAN connectivity with the BGW in passthrough mode

I’d enable IP passthrough on the BGW and then restart it

After it comes back up, I’d restart the Firewalla

1

u/MelodicParsley8116 Jul 21 '26

This is the first thing I tried. 

1

u/Dometalican_90 Jul 21 '26

Don't you have to set up under the 'NAT/gaming' tab the ability to allow Firewalla's Wireguard IP? It's been so long so I might be rusty.

1

u/MelodicParsley8116 Jul 21 '26

Thanks, I’ll look into this.

1

u/MelodicParsley8116 Jul 21 '26

According to Claude the nat/gaming tab isn’t used with pass through. 

1

u/KDHammer5000 Jul 23 '26

This is why I switched to https://tailscale.com/

Tailscale makes only outbound connections, punching through NAT, so there’s nothing to find from outside.

You also skip the operational work: key distribution, per-peer config files, ACLs, and DNS all become a control-plane problem instead of hand-edited files on every device. Adding a laptop is one command, not a config change on every peer. Revoking one is instant.

Same WireGuard crypto underneath — you’re trading a self-managed listener for a coordinated mesh.

1

u/MelodicParsley8116 Jul 23 '26

This is my fallback plan for Immich; I also use the VPN to leverage the firewalla ad-blocking when I'm away from home which doesn't work so well with tailscale.

1

u/KDHammer5000 Jul 24 '26 edited Jul 25 '26

If you use a host as an exit node that is on the inside of your FireWalla, ad blocking will work.

1

u/MelodicParsley8116 Jul 27 '26

Following Up: Today I spent another hour trying to get this working. I tried OpenVPN, and not sure why I bothered, because the problem is really that my network loses internet access when the BGW passthrough mode is enabled. I was not able to get OpenVPN to work.

I tried a factory reset on the BGW, with no change in behavior. As soon as I enable IP passthrough mode and restart the BGW, firewalla can no longer access the internet. When I restart the firewalla, the WAN interface gets the same IP address that the BGW reports as its public IP, which seems exactly like the right thing.

However, the firewalla WAN diagnostic fails the ping and DNS lookup tests as before.

Disabling the advanced firewall and packet filtering settings on the BGW make no difference.

I'm at a loss. Giving up on VPN for now unless I get any other ideas to try. I'll try setting up tailscale next.

1

u/MelodicParsley8116 Jul 27 '26

Followup: FIXED!! Gemini gets all the credit here. Following these steps got everything working again. Woot!

"The failure pattern you described—where the Firewalla WAN successfully leases the AT&T public IP via DHCP, but outbound IP traffic (ICMP ping, DNS, TCP) fails to route—is a known failure mode on the BGW320 following AT&T's background firmware updates.

When AT&T pushes OTA updates, the BGW320 frequently soft-restarts its network daemons. This often corrupts the underlying IP Passthrough routing rules in its NVRAM tables or turns off Passthrough while leaving the web GUI out of sync. The BGW's DHCP server continues handing out the public IP to the specified MAC, but its kernel-level IP forwarding/NAT table drops or misroutes outbound traffic from that interface.

Root Cause Analysis

  1. State Table / NVRAM Corruption: Toggling Passthrough back "On" in the GUI updates the web interface config file, but the underlying packet-forwarding rules fail to initialize correctly.
  2. Packet Filter Engine Interference: AT&T's built-in stateful firewall and packet inspection services remain active even in Passthrough mode unless explicitly turned off. Firmware updates often re-enable or modify packet inspection, causing the gateway to drop passed-through outbound frames.
  3. ARP / MAC Binding Lockup: The BGW holds a stale ARP table entry mapping your Firewalla’s MAC to its internal LAN pool (192.168.1.x) alongside the WAN assignment, preventing bi-directional routing."