Wireguard clients behind the firewall

I have an Android cellphone that I use with Wireguard to connect to my IPFire firewall and this works great, even without doing any firewall rules. The problem is when I arrive back home I lose the connection.
To remedy this I created this rule:

Any problems doing this? Is there a better way?

Hi @networkingdude

I am not exactly understanding what the problem here is. Is your IPFire remote or at your home? If it disconnects when you enter to the Green side I have hard time seeing the problem here as you are physically in the same network as the VPN connection would put you in.

Please enlighten me if I am not understanding you correctly

– Skye

I have an Android phone and utilize the “Always On” VPN function.
The default configuration prevented me from connecting to the VPN from the same network.
These firewall rules allowed me to connect when local.

My question was, is this best practice given my always on VPN requirements.
It currently functions as I would like.

I would say Hair pin NAT. looks right to me.

Thank you for your response!

I’d say if the firewall rule makes everything work with the always on VPN you’re good to go. It shouldn’t cause you any harm as the rule seems correctly configured.

– Skye

1 Like