Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

IPTABLES and PING with Wireguard [RESOLVED]

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
6 posts • Page 1 of 1
Author
Message
lostinspace2011
Apprentice
Apprentice
Posts: 240
Joined: Fri Sep 09, 2005 10:41 pm

IPTABLES and PING with Wireguard [RESOLVED]

  • Quote

Post by lostinspace2011 » Wed Feb 11, 2026 11:01 am

I am trying to setup my firewall to allow me to ping my wireguard client and server interface. I have setup a wireguard tunnel on vpn0 between Host A 10.0.0.1 as the VPN server and Host B with 10.0.0.2 as the VPN client.

However with IPTABLES enabled I am not able to ping 10.0.0.1 from Host B (10.0.0.2)

I have tried a number of rules including:

Code: Select all

#Reject PING
-A INPUT -j REJECT --reject-with icmp-host-prohibited
#Allow PING on vpn0
-A INPUT -i vpn0 -p icmp --icmp-type echo-request -j ACCEPT
-A OUTPUT -o vpn0 -p icmp --icmp-type echo-reply -j ACCEPT
But I am only able to get the PING to work if I disable iptables completely.

I am able to ping other devices on my local network successfully.

Any suggestions are appreciated.
Last edited by lostinspace2011 on Thu Feb 12, 2026 11:51 am, edited 1 time in total.
Top
pietinger
Administrator
Administrator
Posts: 6635
Joined: Tue Oct 17, 2006 5:11 pm
Location: Bavaria

  • Quote

Post by pietinger » Wed Feb 11, 2026 10:34 pm

Is this problem solved with the solution in your other thread ?
https://wiki.gentoo.org/wiki/User:Pietinger --> New at Gentoo
Top
lostinspace2011
Apprentice
Apprentice
Posts: 240
Joined: Fri Sep 09, 2005 10:41 pm

  • Quote

Post by lostinspace2011 » Thu Feb 12, 2026 3:00 am

Unfortunately not
Top
Hu
Administrator
Administrator
Posts: 24401
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Thu Feb 12, 2026 11:40 am

Please show the output of iptables-save from the ping recipient when ping is not working.
Top
lostinspace2011
Apprentice
Apprentice
Posts: 240
Joined: Fri Sep 09, 2005 10:41 pm

  • Quote

Post by lostinspace2011 » Thu Feb 12, 2026 11:50 am

Adding

Code: Select all

-A INPUT -i vpn0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
Seems to have resolved this issue.
Top
Hu
Administrator
Administrator
Posts: 24401
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Thu Feb 12, 2026 3:19 pm

That suggests that you had the ping working properly before. Your problem was you were blocking the pong, so the remote system answered you, but you discarded the answer. The pong is considered to be associated with the connection initiated by the ping, so the conntrack rule allows the pong to arrive.
Top
Post Reply

6 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic