OPNsense Forum

Archive => 23.1 Legacy Series => Topic started by: unclear4all on June 16, 2023, 07:23:51 PM

Title: How to access OPNsense Web GUI from WAN (LAB/VM environment)?
Post by: unclear4all on June 16, 2023, 07:23:51 PM
Hi there!
First post here born from frustration.

Situation:
VMware lab where OPNsense is connected to NAT network (as a WAN) and internal host network (as a LAN - there will be VMs placed here)
that
VMs are supposed to be placed in the internal host network (LAN) and connect to the Internet via OPNsense FW. Because of that I need to be able to manage firewall from "WAN" (my local LAN).

Problem:
No matter what changes in configuration I make it ends up with connections to FW Web GUI being blocked from WAN (Firewall -> Log Files -> Live View: "Default deny / state violation rule)

OPNsense 23.1

What have I tried:

Whatever I do Web GUI is still blocked from WAN. My one clue is "Automatically generated floating route" which always gets "hits" (screenshot attached) blocking every attempt to connect from WAN. It is "last match" rule so from what I understand it should "hit" last after every other rule. Can you guys help? It must be achievable to have OPNsense as a firewall in lab that is manageable from local LAN (WAN for FW) 

Title: Re: How to access OPNsense Web GUI from WAN (LAB/VM environment)?
Post by: bartjsmit on June 17, 2023, 09:51:31 AM
What about creating a flat management network for all your virtual servers? Testing OPNsense under lab conditions with hacks to allow WAN management may not be a true test.