Jump to content
Not connected, Your IP: 13.59.58.68
muelli

ANSWERED wireguard (console) - some sites not responding

Recommended Posts

Hi everyone,

I was playing around with wireguard from the console today and got some strange error.
Some websites are not responding in full or partially not responding., others work flawlessly
Example: www.speedtest.net partially responding, www.reddit.com timeout no server response
DNS is working though.....

I tried adjusting MTU (lowered, raised) same result.
Any ideas what to try?

btw: using wg-quick up/down to establish/destroy the tunnel, so no dedicated client.


edit: to clarify, when using openvpn everything works as expected

Share this post


Link to post
The lowest MTU acceptable to wireguard is 1280. Try that. Too high an MTU will freeze everything or, in some cases, make things erratic. If MTU = 1280 doesn't solve things, your problems are elsewhere. If MTU = 1280 fixes things, try raising it from there to gain a little efficiency. Many systems will work at MTU = 1420 but not higher.  But there is no substitute for a little experimentation.  Note that the maximum usable MTU value may occasionally vary with the server chosen, as it depends on the network between you and the server. 

Share this post


Link to post

neither MTU setting fixes things. It seems the problems lie within the TLS handshake on certain websites.

I debugged this a little further....
to give some perspective, I am running the wireguard tunnel with default MTU 1420 on my router. Browsing from the router with firefox etc works!
The problem starts when using machines that NAT via the tunnel, so I guess this really is a MTU problem.
Havent found a MSS setting so far.....but neither MTU settings work.
 

edit: lowering MTU on the machines behind the NAT fixes the problem. thanks everyone!

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...