# Wireguard Client & iptables

**URL:** https://dietpi.com/forum/t/wireguard-client-iptables/13356
**Category:** Troubleshooting
**Created:** [7 June 2022 19:16 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356 "2022-06-07T19:16:12Z")
**Posts on this page:** 8
**Page:** 3

<div class="post-metadata">

### Author: ![Xperimental](https://dietpi.com/forum/user_avatar/dietpi.com/xperimental/32/1945_2.png) [@Xperimental](https://dietpi.com/forum/u/Xperimental)
#### Post date: [21 June 2022 14:18 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/45 "2022-06-21T14:18:26Z")

</div>

@trendy @Joulinar  
I have tried to open up these ports with the iptables I mentioned before, but connection is still refused when connected to VPN.

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [21 June 2022 22:11 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/46 "2022-06-21T22:11:38Z")

</div>

Since you are using the nfs client you need to reverse the flows.

```auto
PostUp = iptables -I OUTPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p udp -m multiport --dports 111,892,2049 -m state --state NEW,ESTABLISHED -j ACCEPT
PostUp = iptables -I OUTPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p tcp -m multiport --dports 111,892,2049 -m state --state NEW,ESTABLISHED -j ACCEPT
PostUp = iptables -I INPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p udp -m multiport --sports 111,892,2049 -m state --state ESTABLISHED -j ACCEPT
PostUp = iptables -I INPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p tcp -m multiport --sports 111,892,2049 -m state --state ESTABLISHED -j ACCEPT

```

Also the sequence matters, so you need them before the rule which allows only WG interface allow only traffic.

---

<div class="post-metadata">

### Author: ![Xperimental](https://dietpi.com/forum/user_avatar/dietpi.com/xperimental/32/1945_2.png) [@Xperimental](https://dietpi.com/forum/u/Xperimental)
#### Post date: [22 June 2022 07:29 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/47 "2022-06-22T07:29:50Z")

</div>

Ah, thanks!  
Why before the rule which only allows WG traffic? Doesn’t the WG iptables overule this?

Anyway, it didn’t solve the issue, but I learned something new 🙂

These ports are used when the VPN is down.

```auto
root@DietPi:~# rpcinfo -p 192.168.1.101
   program vers proto port service
    100000 4 tcp 111 portmapper
    100000 3 tcp 111 portmapper
    100000 2 tcp 111 portmapper
    100000 4 udp 111 portmapper
    100000 3 udp 111 portmapper
    100000 2 udp 111 portmapper
    100005 1 udp 892 mountd
    100005 1 tcp 892 mountd
    100005 2 udp 892 mountd
    100005 2 tcp 892 mountd
    100005 3 udp 892 mountd
    100005 3 tcp 892 mountd
    100003 2 tcp 2049 nfs
    100003 3 tcp 2049 nfs
    100003 4 tcp 2049 nfs
    100003 2 udp 2049 nfs
    100003 3 udp 2049 nfs
    100021 1 udp 39904 nlockmgr
    100021 3 udp 39904 nlockmgr
    100021 4 udp 39904 nlockmgr
    100021 1 tcp 39607 nlockmgr
    100021 3 tcp 39607 nlockmgr
    100021 4 tcp 39607 nlockmgr
    100024 1 udp 33760 status
    100024 1 tcp 33798 status

```

`nlockmgr` and `status` use variable ports. Do I need to hard strap them in `DietPi`?  
I have read something about hard strapping here: [Firewalling a Linux NFS server with iptables -- Prefetch Technologies](https://prefetch.net/blog/2010/11/02/firewalling-a-linux-nfs-server-with-iptables/)  
If so, where can I find the config file in DietPi?

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [22 June 2022 08:21 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/48 "2022-06-22T08:21:56Z")

</div>

> [@Xperimental](#):
>
> Why before the rule which only allows WG traffic? Doesn’t the WG iptables overule this?

iptables rules are scanned from top to bottom. First rule which matches is applied and scanning stops.

> [@Xperimental](#):
>
> If so, where can I find the config file in DietPi?

The tutorial is describing the process on the server part. You are trying to connect from the client side. If you cannot hardcode these ports on the NAS, then it would save you some time to allow all traffic to the IP of the NAS instead of opening specific ports.

---

<div class="post-metadata">

### Author: ![Xperimental](https://dietpi.com/forum/user_avatar/dietpi.com/xperimental/32/1945_2.png) [@Xperimental](https://dietpi.com/forum/u/Xperimental)
#### Post date: [22 June 2022 08:31 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/49 "2022-06-22T08:31:40Z")

</div>

Yes, maybe that’s easier.

I removed the ports, but that doesn’t work…

```auto
PostUp = iptables -I INPUT 1 -i eth0 -p tcp -s 192.168.1.0/24 --dport 22 -j ACCEPT
PostUp = iptables -I OUTPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p udp -m state --state NEW,ESTABLISHED -j ACCEPT
PostUp = iptables -I OUTPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p tcp -m state --state NEW,ESTABLISHED -j ACCEPT
PostUp = iptables -I INPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p udp -m state --state ESTABLISHED -j ACCEPT
PostUp = iptables -I INPUT 1 -s 192.168.1.0/24 -d 192.168.1.0/24 -p tcp -m state --state ESTABLISHED -j ACCEPT
PostUp = iptables -I OUTPUT 1 -o eth0 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
PostUp = iptables -I OUTPUT 2 ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT
PostUp = systemctl start transmission-daemon
PreDown = iptables -D INPUT -i eth0 -p tcp -s 192.168.1.0/24 --dport 22 -j ACCEPT && iptables -D OUTPUT -o eth0 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT && ipt>
PreDown = systemctl stop transmission-daemon

```

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [22 June 2022 09:53 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/50 "2022-06-22T09:53:09Z")

</div>

> [@Xperimental](#):
>
> `PostUp = iptables -A OUTPUT ! -o %i -m mark ! --mark $(wg show %i fwmark) -m addrtype ! --dst-type LOCAL -j REJECT`

Otherwise it always gets the second position and everything else underneath it will never match.

---

<div class="post-metadata">

### Author: ![Xperimental](https://dietpi.com/forum/user_avatar/dietpi.com/xperimental/32/1945_2.png) [@Xperimental](https://dietpi.com/forum/u/Xperimental)
#### Post date: [22 June 2022 10:06 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/51 "2022-06-22T10:06:19Z")

</div>

Yes, it’s fixed now! Thanks!!

---

<div class="post-metadata">

### Author: ![trendy](https://dietpi.com/forum/user_avatar/dietpi.com/trendy/32/61_2.png) [@trendy](https://dietpi.com/forum/u/trendy)
#### Post date: [22 June 2022 10:09 UTC](https://dietpi.com/forum/t/wireguard-client-iptables/13356/52 "2022-06-22T10:09:08Z")

</div>

I’m glad we sorted it out. 🙂

[Previous page](https://dietpi.com/forum/t/wireguard-client-iptables/13356.md?page=2)
