OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Firewall rule gateway change not routing correctly?
« previous next »
  • Print
Pages: [1]

Author Topic: Firewall rule gateway change not routing correctly?  (Read 1561 times)

kdackiw

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Firewall rule gateway change not routing correctly?
« on: December 18, 2018, 11:55:34 pm »
Hi all.  Coming over from pf and setting up again.

I typically run VPN connections whilst maintaining my standard ISP gateway.  I typically sort things out with policy routing.

The standard firewall rule on the LAN to route to the default gateway is all fine and works as expected.
When I manually change the gateway to forcibly be the WAN_DHCP (the correct IP also shows in the pulldown) then nothing routes out.

I also have the WAN_DHCP gateway set to default as well explicitly.

I have also looked at the NAT and don't see any issues there either.

I can't see this being a bug so I am doing something wrong and not picking it up.

Help?  TY.

Kev.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: Firewall rule gateway change not routing correctly?
« Reply #1 on: December 19, 2018, 06:06:54 am »
Screenshot or rules and outbound Nat please
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

kdackiw

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Firewall rule gateway change not routing correctly?
« Reply #2 on: December 19, 2018, 09:27:50 pm »
I believe that this may be solved.

If the default LAN pass rule is set to "default" gateway then it seems to implicitly allow LAN-LAN traffic.
It appears that in this setup, my internal DNS server is accessible.

If I modify the default LAN pass rule and explicitly set the gateway to my ISP, then I must add a LAN-LAN pass rule above this rule as it seems suddenly LAN traffic is not allowed.

Is this by design or an oversight?  It's not a bad thing to have the LAN-LAN rule but shouldn't it be there by default from the initial setup?

Kev.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Firewall rule gateway change not routing correctly?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2