OPNsense® ☞ ؟⸮UNOFFICIAL⸮؟ – Self Support Community for community self support.

119 Members
"OPNsense is open source, FreeBSD-based firewall and routing software developed by Deciso, a company in the Netherlands that makes hardware and sells support packages for OPNsense. It is a fork of pfSense." - https://en.wikipedia.org/wiki/OPNsense ° pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a physical computer or a virtual machine to make a dedicated firewall/router for a network and has been noted for its reliability and offering a range of features. - https://en.wikipedia.org/wiki/PfSense

6 Sep 2020
@jeff_hallam:matrix.orgjeff_hallamCan't seem to redirect DNS traffic from LAN1 to a host on LAN2. I have NAT set to catch and redirect to the LAN2 host and have a rule on LAN1 to allow the traffic to the LAN2 host.22:07:30
@MilkManzJourDaddy:matrix.orgMMJD-MxO Have you tried the diagnostics, i.e. pinging one LAN I.P. from the other? ...I.e. ping from, or also pinging the desired local-host. The C.I.D.R. ranges are correct? The I.P. ranges are okay by whatever D.H.C.P. you have set? Have you tried static instead of DHCP? 23:44:20
@jeff_hallam:matrix.orgjeff_hallamIt's related to DNS specifically and I'm not necessarily letting ping protocols between LANs. The internal NAT redirect works for LAN1 (forces DNS through my chosen server) but when watching the live log, the request from LAN2 hits a default deny rule.23:56:37
21 Sep 2020
@MilkManzJourDaddy:matrix.orgMMJD-MxORight, but sometimes we miss the basics. But you lost me with that last parsing as I'm unclear if you mean LAN2 should be able to reach LAN1 also, or LAN2 to WAN. 01:33:10
@jeff_hallam:matrix.orgjeff_hallamSorry, I'll rephrase later today after work10:32:16
@jeff_hallam:matrix.orgjeff_hallamSo many hours spent on this... I'm hitting a default deny rule with traffic from 192.168.50.X to (my local dns server). I have a pass rule on the 50.X subnet allowing dns traffic to
@jeff_hallam:matrix.orgjeff_hallamIt works fine for VLANs to access the common dns server but not separate networks (the 50.X).15:53:03
@MilkManzJourDaddy:matrix.orgMMJD-MxOAnd, just to check some basics, you have your pass rule above/higher-priority than the default block rule so it's followed first? 16:04:30

