sending handshake handshake not completed

A WireGuard "handshake did not complete" error 

usually indicates a communication breakdown between client and server, often caused by incorrect endpoint IPs, firewall blocking port 51820/UDP, or mismatched public/private keys. Fixes include verifying configurations, using PersistentKeepalive = 25 for NAT traversal, and checking for time synchronization issues. 

Here are the most effective troubleshooting steps:

1. Check Configuration Keys (Most Common) 

Public Key Mismatch: Ensure the client's public key is correctly pasted into the server configuration, and the server's public key is correctly in the client's configuration.AllowedIPs: Check that the client AllowedIPs includes the VPN server subnet (e.g., 0.0.0.0/0 or 10.0.0.0/24). 

2. Firewall and Port Forwarding

UDP Port: WireGuard uses UDP, not TCP. Ensure your server firewall is allowing UDP traffic on the port specified in the config (default: 51820).Port Forwarding: If the server is behind a router, ensure port forwarding is active for the chosen UDP port to the server's local IP, say Reddit users. 

3. Networking & NAT Issues

Persistent Keepalive: If the client is behind a firewall or using mobile data, add PersistentKeepalive = 25 to the [Peer] section of the client configuration.Endpoint IP: Ensure the client is targeting the correct public IP address and port of the server. 

OPNsense Forum +1

4. System Time

Time Synchronization: A time difference (skew) of more than a few minutes between the client and server will cause handshake failures, suggest Reddit users. 

5. MTU Issues

Lower MTU: Mobile networks or specific ISPs may require a smaller packet size. Try adding MTU = 1360 to the [Interface] section of the client configuration, recommend Reddit users. 

Typical Quick Fixes

Restart the WireGuard service on the server.
