<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wireguard VPN inaccessible from WAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871050#M1102483</link>
    <description>&lt;P&gt;I tried to enable it but I received this error:&lt;/P&gt;&lt;DIV class=""&gt;&lt;FONT face="terminal,monaco"&gt;You cannot select the Perform Route Lookup option if you select interface for translated source&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;FONT face="terminal,monaco"&gt;The Perform Route Lookup option is available for identity NAT only. The original and translated source networks must be identical to use the option.&lt;/FONT&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 10 Jul 2023 14:03:36 GMT</pubDate>
    <dc:creator>Exor</dc:creator>
    <dc:date>2023-07-10T14:03:36Z</dc:date>
    <item>
      <title>Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4869957#M1102412</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I made a Wireguard VPN server in Proxmox with no internal firewall. Our firewall is Cisco Firepower 1120 which manages all the aspects.&lt;/P&gt;&lt;P&gt;I have tested connecting to VPN server from within LAN and it worked but no internet access, I added iptables and now it's working. So, I know VPN server is working. I am still not able to connect to the VPN server from outside of LAN. Wireguard is not able to handshake with the server.&lt;/P&gt;&lt;P&gt;This might be ip/port forwarding issue. I may be missing something. I have the following set up already below. Let me know if I am missing something? Any help is appreciated!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Exor_1-1688760640662.png" style="width: 500px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189750i02A6D0BF4813EED2/image-dimensions/500x390?v=v2" width="500" height="390" role="button" title="Exor_1-1688760640662.png" alt="Exor_1-1688760640662.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Exor_2-1688760710888.png" style="width: 718px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189751iE4F2C1AF92F104BF/image-dimensions/718x473?v=v2" width="718" height="473" role="button" title="Exor_2-1688760710888.png" alt="Exor_2-1688760710888.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 20:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4869957#M1102412</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-07T20:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870050#M1102425</link>
      <description>&lt;P&gt;simple topology can help me here,&amp;nbsp;&lt;BR /&gt;you config Server INside, the client of Server INside or OUTside ?&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 07:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870050#M1102425</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-08T07:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870511#M1102446</link>
      <description>&lt;P&gt;What that VPN port is? Did you make sure that the firewall itself is not running any VPN services on the same port? Not sure if the firewall would return any error in that case when you try to configure the NAT rule.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2023 23:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870511#M1102446</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-09T23:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870967#M1102472</link>
      <description>&lt;P&gt;Server is inside and client is outside. This is not working.&lt;/P&gt;&lt;P&gt;Server is inside and client is inside (using local ip). VPN is working&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870967#M1102472</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T12:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870975#M1102473</link>
      <description>&lt;P&gt;VPN port is 51820. Firepower is not running any VPN services; we do not have license for it which is why I am testing Wireguard VPN server instead. I can confirm there is no duplicate port being used in Firepower's ports list.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870975#M1102473</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T12:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870977#M1102474</link>
      <description>&lt;P&gt;Server INside Client OUTside not working&amp;nbsp;&lt;BR /&gt;you need&amp;nbsp;&lt;BR /&gt;static NATing for Private Server IP to FPR OUTside public IP for specific Port (port Server use), did you add this NATing rule ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870977#M1102474</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-10T12:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870981#M1102475</link>
      <description>&lt;P&gt;Yes, I have added the NAT rule mentioned in my original post, there is a snip of it. Is there anything I am missing in the NAT rule?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 12:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870981#M1102475</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T12:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870982#M1102476</link>
      <description>&lt;P&gt;I don't see anything wrong with your NAT or security rule, assuming the VPN-Server IP is configured with the real private IP address of the server. Could it be a block on the ISP router? do you know if NAT'ing is applied to their device? if so, then that should be disabled and the NAT should only be on the firewall, or the NAT on the firewall should be turned off and configured on the ISP router. Also, if you run packet capture on the firewall outside interface for any traffic destined to port 51820, do you see any traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870982#M1102476</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-10T13:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870986#M1102477</link>
      <description>&lt;P&gt;port, you need to specify port, that what missing in your NAT&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4870986#M1102477</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-10T13:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871014#M1102480</link>
      <description>&lt;P&gt;The Source Port is set to VPN which I created is set to 51820 as mentioned in the snip. If that's not what you are talking about, please let me know.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871014#M1102480</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T13:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871018#M1102481</link>
      <description>&lt;P&gt;Yes, the VPN-Server is set to 192.168.1.158 which is a local IP. I have tried to look into capture but found this instead:&lt;/P&gt;&lt;P&gt;&lt;FONT face="terminal,monaco"&gt;translate_hits = 4567, untranslate_hits = 4317&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco"&gt;10 (inside) to (outside) source static VPN-Server interface service _|NatOrigSvc_711a30b9-1cc9-11ee-a336-17761654d6de _|NatMappedSvc_711a30b9-1cc9-11ee-a336-1776165&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="terminal,monaco"&gt;4d6de&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this is something. Seems to be showing that the NAT is getting hit.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871018#M1102481</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T13:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871035#M1102482</link>
      <description>&lt;P&gt;in advance of NAT edit&amp;nbsp;&lt;BR /&gt;there is route-lookup option ? if yes enable it.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 13:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871035#M1102482</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-10T13:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871050#M1102483</link>
      <description>&lt;P&gt;I tried to enable it but I received this error:&lt;/P&gt;&lt;DIV class=""&gt;&lt;FONT face="terminal,monaco"&gt;You cannot select the Perform Route Lookup option if you select interface for translated source&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;FONT face="terminal,monaco"&gt;The Perform Route Lookup option is available for identity NAT only. The original and translated source networks must be identical to use the option.&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871050#M1102483</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T14:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871057#M1102484</link>
      <description>&lt;P&gt;how many public IP you beside the OUTside public IP ?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871057#M1102484</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-10T14:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871059#M1102485</link>
      <description>&lt;P&gt;We have only one public IP.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871059#M1102485</guid>
      <dc:creator>Exor</dc:creator>
      <dc:date>2023-07-10T14:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871075#M1102486</link>
      <description>&lt;P&gt;can you share packet tracer you test&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871075#M1102486</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-10T14:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Wireguard VPN inaccessible from WAN</title>
      <link>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871490#M1102515</link>
      <description>&lt;P&gt;Yes that shows the NAT hits, but I would try to run packet capture on the outside interface with the command "cap &amp;lt; name &amp;gt; interface outside match tcp any host &amp;lt; the outside interface IP&amp;gt; eq&amp;nbsp;&lt;SPAN&gt;51820". If that port is a UDP port then please change the tcp keyword on the capture command to udp. Also, as you don't have any hits on the security rule you created, I'm wondering if there is any security policy above that one that is denying the traffic coming from the outside towards the server, worth checking.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 07:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wireguard-vpn-inaccessible-from-wan/m-p/4871490#M1102515</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-11T07:16:54Z</dc:date>
    </item>
  </channel>
</rss>

