WireGuard Routing & DNS Fix
Budget: $30 – $250 USD
I have a PFsense firewall in a colocation rack and a Unifi gateway at the office joined by a WireGuard tunnel. The goal is to make a block of public IP addresses that live at the datacenter appear at the office end, routed directly—no NAT—so devices on-site can use those addresses as if they were local.
Where I’m stuck
• From the office I can ping the public IPs of services in the colo, but the site content itself won’t load. I believe this is due to an issue with NAT
• The tunnel itself is up and stable; the problem is routing policy and DNS behavior once the packets cross.
• I’m unsure if this is the “right way” to do things.
What I need from you
– Jump in immediately, inspect the existing WireGuard config, routing tables, and DNS settings, identify the break.
– Either correct the current design or propose a cleaner approach; I’m open to replacing the Unifi with another PFsense instance if that simplifies things.
– Keep IPsec off the table (the office WAN is DHCP).
– Deliver working routing for the public /29 over the tunnel plus clear documentation of what was changed so I can maintain it.
Timing is tight—ASAP resolution is appreciated. If this sounds straightforward to you and you’re fluent with PFsense, Unifi, and WireGuard, let’s get started.
I will provide a current architecture diagram, a suggested architecture, and any access needed to complete the tasks.
Where I’m stuck
• From the office I can ping the public IPs of services in the colo, but the site content itself won’t load. I believe this is due to an issue with NAT
• The tunnel itself is up and stable; the problem is routing policy and DNS behavior once the packets cross.
• I’m unsure if this is the “right way” to do things.
What I need from you
– Jump in immediately, inspect the existing WireGuard config, routing tables, and DNS settings, identify the break.
– Either correct the current design or propose a cleaner approach; I’m open to replacing the Unifi with another PFsense instance if that simplifies things.
– Keep IPsec off the table (the office WAN is DHCP).
– Deliver working routing for the public /29 over the tunnel plus clear documentation of what was changed so I can maintain it.
Timing is tight—ASAP resolution is appreciated. If this sounds straightforward to you and you’re fluent with PFsense, Unifi, and WireGuard, let’s get started.
I will provide a current architecture diagram, a suggested architecture, and any access needed to complete the tasks.