Proton Wireguard 4.8.1 MT-3000 not working

Based on our inspection, it looks like your network is blocking the WireGuard protocol.


The packet capture shows UDP/WireGuard traffic is being dropped, while ICMP to the server still works.

The WireGuard log shows a REKEY-GIVEUP error, which indicates the tunnel failed to rekey because the peer never completed the handshake:

Wed Nov  5 01:44:12 2025 user.notice wireguard-debug: USER=root ifname=wgclient1 ACTION=REKEY-GIVEUP SHLVL=1 HOME=/ HOTPLUG_TYPE=wireguard LOGNAME=root DEVICENAME= TERM=linux SUBSYSTEM=wireguard PATH=/usr/sbin:/usr/bin:/sbin:/bin PWD=/


The same WireGuard config works locally on our MT3000 (v4.8.1), so the issue may be specific to the network.

Meanwhile, another profile using port 443 is functioning properly on your router—meaning the firmware's WireGuard can operate normally.


We recommend further investigation:

  1. Verify the config from another device on the same network (for example, a smartphone) to see if it can establish the tunnel.
  2. Connect the MT3000 to a mobile hotspot (or another ISP) and test. If it connects there, the original ISP/network is blocking WireGuard UDP.

If censorship is confirmed, you may consider using AmneziaWG with obfuscated encryption.