Hi guys,
I have setup OPNSense on vmware as my firewall/gateway, between two networks:
-LAN - 10.0.0.0/8
- DMZ - 192.168.0.0/24
This works fine, however, and this is probably easy and very fundamental. I want to route traffic from the DMZ to the LAN, for certain applications. For example, an app on the DMZ web servers needs to report back to a server in the LAN, ie a deployment server, etc.
How can I setup routing on OPNSense to fulfil this?
OPNsense does route between all interfaces by default. What you need is a firewall rule to permit the traffic to pass.
Hi,
as a OPNSense newbie,
can you post an example ?
my IF
LAN: 192.168.168.0
IPCam: 192.168.0.0
Now i want to access the IPCam Net from the LAN Net
regards,
Jürgen
Should be working already. The default installation has got an "allow all" rule for LAN. Devices on LAN can access everything including your camera network.
You need to set up DHCP for the camera network, otherwise the camera(s) probably won't get an address and a default gateway.
Hi,
the internal routing works, but I can't access the Internet.
my Configuration
Fritzbox: IP 192.168.1.1/24
OPNSense:
WAN Interface 192.168.1.2/24
LAN Interface 192.168.168.112/24 dhcp for clients ON
OPT1 Interface(IPCam) 192.168.0.1/24 dhcp for clients ON
Internal routing between LAN<-> OPT1 OK
Outgoing LAN -> WAN -> FB doesn't work
Settings:
Disable outbound NAT rule generation - (outbound NAT is disabled)
FIREWALL: RULES: WAN
Action Direction Protocol Source Port Destination Port Gateway Schedule Description
Pass in IPv4 * * * * * * *
SYSTEM: GATEWAYS: SINGLE
Name Interface Protocol Priority Gateway Monitor IP RTT RTTd Loss Status Description
WAN_Gateway (active) WAN IPv4 20 (upstream) 192.168.1.1 ~ ~ ~ Online Interface WAN_Gateway
If you disable outbound NAT your Fritzbox needs two static routes:
Network: 192.168.168.0
Netmask: 255.255.255.0
Gateway: 192.168.1.2
Network: 192.168.0.0
Netmask: 255.255.255.0
Gateway: 192.168.1.2
if you do not control your Fritzbox because it belongs to your provider or some such, you must NAT.
Hi,
thanks for the resolution. Now it works.
regards
Jürgen