I've had a working and stable Proton/Wireguard configuration working on my WRT3200ACM home router (running OpenWrt 25.12.5) for over a month but when I got up this morning, I had no Internet access from my home devices. Then, after rebooting and restoring my router, the VPN was saturating on the uplink (TX) all by itself, being that there was no corresponding traffic on any of my router's other interfaces. The router runs fine and carries all my traffic if I stop the VPN, but each time I restart the VPN, the upstream traffic saturates again immediately (300Mb/s). I tried moving the VPN to another Proton server and I reinstalled the WireGuard software but that did not help. Any advice?
Run something to see what traffic is going over the VPN interface when it is active.
One option is iftop at the command line (ssh to the router, might need to be installed it is not by default) limited to the VPN interface (-i parameter to iftop ). Can show from/to IP address, amount of traffic and optionally port.
iftop cannot find my VPN interface (wg0), but does work if I specify another interface (wan).
root@OpenWrt:~# iftop -i wg0
interface: wg0
Error getting hardware address for interface: wg0
ioctl(SIOCGIFHWADDR): No such device
Unable to get IP address for interface: wg0
ioctl(SIOCGIFADDR): No such device
pcap_open_live(wg0): wg0: No such device exists (No such device exists)
I notice that using Luci, Interfaces/Devices shows wg0 has no MAC address. All my other interface do. Maybe I need to recreate wg0?
wgo <> wg0 ?
sorry, my typo, but my reply is good for wg0
Sometimes servers are just down or malfunctioning or your subscription ended ![]()
If you did a full reinstall check the guide:
WireGuard Client Setup Guide
Odd, what does wg show give? (might need to install wireguard-tools )
root@OpenWrt:~# wg show
interface: wg0
public key: XB/zYqC2JAmoJPL8Kdt/s70C+psrr7J6qW4ZMDLmKws=
private key: (hidden)
listening port: 38878
peer: cNX/YyffJbphICRzBE9FJCbZYMhPJ45arC76PYyjoig=
endpoint: 149.34.251.129:51820
allowed ips: 0.0.0.0/0, ::/0
latest handshake: 21 seconds ago
transfer: 92 B received, 366.85 MiB sent
persistent keepalive: every 25 seconds
A few bytes can indicate a routing problem, Please connect to your OpenWRT device [using ssh](https://openwrt.org/docs/guide-quick-start/sshadministration) and copy the output of the following commands and post it here using the "Preformatted text button: </>"
Remember to redact keys, passwords, MAC addresses and any public IP addresses you may have but do not redact private [RFC 1918](https://en.wikipedia.org/wiki/Private_network) IP addresses (192.168.X.X, 10.X.X.X and 172.16-32.X.X) as that is not needed:
ubus call system board
cat /etc/config/network
cat /etc/config/firewall
ip route show
ip -6 route show
But could also be a routing problem on the server side
First guess would be to check if masquerading is enabled on the WG interface
I have the same problem on two servers, so server seems good. My Proton subscription is good. I went through the guide you provided and everything looks good, but I still have the same problem.
Also check if your router is working if WG is disabled to get a baseline
root@OpenWrt:~# ubus call system board
{
"kernel": "6.12.94",
"hostname": "OpenWrt",
"system": "ARMv7 Processor rev 1 (v7l)",
"model": "Linksys WRT3200ACM",
"board_name": "linksys,wrt3200acm",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "25.12.5",
"firmware_url": "https://downloads.openwrt.org/",
"revision": "r33051-f5dae5ece4",
"target": "mvebu/cortexa9",
"description": "OpenWrt 25.12.5 r33051-f5dae5ece4",
"builddate": "1782737960"
}
}
config wireguard_wg0
option description 'Imported peer configuration'
option public_key '*****'
option persistent_keepalive '25'
option endpoint_host '*****'
option endpoint_port '51820'
option route_allowed_ips '1'
list allowed_ips '0.0.0.0/0'
list allowed_ips '::/0'
root@OpenWrt:~# cat /etc/config/firewall
config defaults
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option synflood_protect '1'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'lan'
option mtu_fix '1'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
list device 'wan'
list network 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
option enabled '1'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
option enabled '1'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
option enabled '1'
config zone
option name 'vpn'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
list network 'wg0'
option masq '1'
option mtu_fix '1'
config forwarding
option src 'lan'
option dest 'vpn'
config forwarding
option src 'lan'
option dest 'wan'
config zone
option name 'guest'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'guest'
config forwarding
option src 'guest'
option dest 'vpn'
config rule
option src 'guest'
option name 'Allow-DNS-Guest'
option dest_port '53'
option target 'ACCEPT'
option enabled '1'
config rule
option src 'guest'
option name 'Allow-DHCP-Guest'
list proto 'udp'
option dest_port '67'
option target 'ACCEPT'
option enabled '1'
config forwarding
option src 'guest'
option dest 'wan'
root@OpenWrt:~# ip route show
default dev wg0 proto static scope link metric 10
default via 192.168.1.254 dev wan proto static src 192.168.1.68 metric 20
10.2.0.2 dev wg0 proto static scope link metric 10
192.168.1.0/24 dev wan proto static scope link metric 20
192.168.5.0/24 dev br-guest proto kernel scope link src 192.168.5.1
192.168.10.0/24 dev br-lan proto kernel scope link src 192.168.10.1
oot@OpenWrt:~# ip -6 route show
***** dev wg0 proto static metric 10 pref medium
fd37:66bf:5809::/64 dev br-lan proto static metric 1024 pref medium
unreachable fd37:66bf:5809::/48 dev lo proto static metric 2147483647 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev wan proto kernel metric 256 pref medium
fe80::/64 dev br-guest proto kernel metric 256 pref medium
default dev wg0 proto static metric 10 pref medium
You trimmed out too much of /etc/config/network , need the config interface 'wg0' section. Or are some scripts bringing wg up and creating the interface on demand?
Could also look into using tcpdump to see what that 100's MB of blind traffic is if iftop hasn't helped (use iftop after the interface is up if scripts are creating the interface on demand).
It is odd that almost nothing is coming back out of the tunnel. Also odd that something is sending so much traffic blind (with no response).
Just to see what Wireguard you have installed / are running can you show the output of:
apk list --installed | grep -Ei 'wireguard|proton|amnezia|obfus'
config interface 'wg0'
option proto 'wireguard'
option private_key '*****'
list addresses '10.2.0.2/32'
list addresses '*****/128'
list dns '10.2.0.1'
list dns '*****'
option multipath 'off'
option metric '10'
Not that I am aware of.
root@OpenWrt:~# apk list --installed | grep -Ei 'wireguard|proton|amnezia|obfus
>
no output other than the carrot ... do I need to enter another command?
Please show full output (redacted for MAC address)
and also:
ifconfig
Here is my output from tcpdump, it repeats endlessly.
root@OpenWrt:~# killall tcpdump; tcpdump -n -i wg0
09:06:59.322020 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 112
09:06:59.322031 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 176
09:06:59.322040 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 240
09:06:59.322048 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 304
09:06:59.322057 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 368
09:06:59.322068 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 432
09:06:59.322075 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 496
09:06:59.322087 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 560
09:06:59.322097 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 624
09:06:59.322106 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 688
09:06:59.322118 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 752
09:06:59.322132 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 816
09:06:59.322140 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 880
09:06:59.322157 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 944
09:06:59.322178 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1008
09:06:59.322191 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1072
09:06:59.322223 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1136
09:06:59.322277 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1200
09:06:59.322365 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1264
09:06:59.322380 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1328
09:06:59.322487 IP 10.2.0.2.43018 > 149.34.251.129.51820: UDP, length 1452
09:06:59.322493 IP 10.2.0.2 > *****: ip-proto-17
my router works fine when WG is disabled
That looks like a routing loop. The traffic between the VPN endpoint and you has to go over the WAN and not through the wireguard tunnel. Check routing for the VPN endpoint (use correct tunnel address):
ip route get 149.34.251.129
should say
149.34.251.129 via 192.168.1.254 dev wan
and not
149.34.251.129 dev wg0
What looks to be happening - packet is sent to the VPN endpoint, it is sent INSIDE the tunnel instead of over the WAN. That generated more traffic for the VPN which also gets sent inside the tunnel + some VPN overhead. Repeat until all bandwidth is used up.
root@OpenWrt:~# cat /etc/config/network
config interface 'wg0'
option proto 'wireguard'
option private_key '*****'
list addresses '10.2.0.2/32'
list addresses '*****/128'
list dns '10.2.0.1'
list dns '*****'
option multipath 'off'
option metric '10'
root@OpenWrt:~# ifconfig
wg0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.2.0.2 P-t-P:10.2.0.2 Mask:255.255.255.255
inet6 addr: 2a07:b944::2:2/128 Scope:Global
UP POINTOPOINT RUNNING NOARP MTU:1420 Metric:1
RX packets:1 errors:0 dropped:0 overruns:0 frame:0
TX packets:777876 errors:0 dropped:36962 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:92 (92.0 B) TX bytes:586922340 (559.7 MiB)
routing looks okay ...
root@OpenWrt:~# ip route get 149.34.251.129
149.34.251.129 via 192.168.1.254 dev wan src 192.168.1.68 uid 0
cache