Why can't Wireshark detect Wireguard interface used by Mozilla VPN?

Viewed 2864

Running Wireshark 3.2.5 64bit on Windows 10 as administrator.

Mozilla VPN creates this interface as shown in IPCONFIG

Unknown adapter FirefoxPrivateNetworkVPN:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : WireGuard Tunnel
   Physical Address. . . . . . . . . :
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : fc00:bbbb:bbbb:bb01::*:*(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.65.*.*(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.255
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : 10.64.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Wireshark does not display this interface, although all other interfaces (real and virtual) are available.
I can see the encrypted data on the primary Ethernet interface. I need Wireshark to monitor the traffic going through the Wireguard tunnel. Other VPNs interfaces are visible in Wireshark, why not this one?

1 Answers

I have also noticed that Windows Wireguard implementation currently doesn't cooperate with other standard network tools. Not only WG interfaces are invisible to Wireshark, Wireshark connections could not be blocked by Windows Firewall for some reason. I see it as a security issue.

Currently Wireguard for Windows uses Wintun interface. For comparison, OpenVPN has had an option to use Wintun interface for some time now too. And when you use it its interface is also invisible to Wireshark. But you can still block OpenVPN in the Windows Firewall.

EDIT:

Solution (2021-08-22): Update npcap Windows driver to the most recent one. Then Wintun interfaces will appear for Wireshark.

Now the problem is that Wireshark currently incorrectly dissects what it captures on the Wintun interface - it sees "Ethernet II" packets going around with unknown protocol 0xXXXX inside, while actually it's IPv4 packets not "Ethernet II", and 0xXXXX is just a part of an IP address. The data is not encrypted though, so you can identify packets by data contents: for example, it's an ICMP echo on the screenshot.

2

Related