# Wireguard handshake timeout with loadbalancer set up

**URL:** <https://forum.pritunl.com/t/wireguard-handshake-timeout-with-loadbalancer-set-up/3117>\
**Category:** Pritunl VPN\
**Created:** [March 14, 2025, 4:08pm UTC](https://forum.pritunl.com/t/wireguard-handshake-timeout-with-loadbalancer-set-up/3117 "2025-03-14T16:08:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![OlegY](https://forum.pritunl.com/user_avatar/forum.pritunl.com/olegy/32/1230_2.png) [@OlegY](https://forum.pritunl.com/u/OlegY)\
**Post date:** [March 14, 2025, 4:08pm UTC](https://forum.pritunl.com/t/wireguard-handshake-timeout-with-loadbalancer-set-up/3117/1 "2025-03-14T16:08:13Z")

</div>

Hello. I’m trying to set up the following architecture: I’m using a load balancer in a public subnet with a certificate. My DNS is pointing to it. The Pritunl server is located in a private subnet, so it has no public IP. I set the Public Address as my DNS name. I also set the same Sync Address in the advanced host section. Pritunl settings are configured as follows:

- `sudo pritunl set app.reverse_proxy true`
- `sudo pritunl set app.redirect_server false`
- `sudo pritunl set app.server_ssl false`
- `sudo pritunl set app.server_port 80`

I am able to successfully connect with OpenVPN, but WireGuard fails with a “Handshake timeout” on my server. In the logs, I see only that the user authenticated successfully but then disconnected without any clear errors. To be more specific, on the load balancer I have 3 listeners:

- HTTPS on port 443 pointing to HTTP port 80 on the Pritunl server
- TCP on port 1111 pointing to TCP port 1111 on Pritunl (for OpenVPN)
- UDP on port 2222 pointing to UDP port 2222 on Pritunl (for WireGuard)

Can someone point me in the right direction?

---

<div class="post-metadata">

**Author:** ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)\
**Post date:** [March 17, 2025, 12:45pm UTC](https://forum.pritunl.com/t/wireguard-handshake-timeout-with-loadbalancer-set-up/3117/2 "2025-03-17T12:45:22Z")

</div>

If the server has no public IP address either port forwarding or a network load balancer with UDP support will need to be used.
