OPNsense Forum

Archive => 24.1, 24.4 Legacy Series => Topic started by: kug1977 on May 31, 2024, 09:50:52 AM

Title: Doesn't understand that firewall behavior
Post by: kug1977 on May 31, 2024, 09:50:52 AM
Hi,

I'm kind of blind, where to look for issues anymore. It is OPNsense 24.1.7_4-amd64

I have two vLANs
020_equipment 10.1.20.1/23
100_trusted_clients 10.1.100.1/23

I have two floating rules, that have these interfaces assigned, saying

I can ping

but I cannot ping 10.1.101.68 to 10.1.21.20, while the life view of the firewall shows green for the ICMP packages.

(http://screenshot%20from%202024-05-31%2009-40-41.png)
(http://screenshot%20from%202024-05-31%2009-40-41.png)
Title: Re: Doesn't understand that firewall behavior
Post by: Patrick M. Hausen on May 31, 2024, 09:55:27 AM
Does 10.1.21.20 have a proper default gateway configured?
Title: Re: Doesn't understand that firewall behavior
Post by: meyergru on May 31, 2024, 10:00:41 AM
What types of clients are these?

Because if the firewall shows the ICMP packets as passing, I would guess that the target simply does not answer. This would be the case for Windows machines, which by default only answer to pings from their local subnet unless you change the local Windows firewall rules.
Title: Re: Doesn't understand that firewall behavior
Post by: kug1977 on May 31, 2024, 01:37:20 PM
the IP address 10.1.21.20 is assigned to a network printer.

This printer was reachable via HTTPS Admin GUI and pingable in the past. And it answers pings to the OPNsense, when using the built in ping command from the gateway of
and nothing changed on the printer setup. The only I changed was setting up the firewall fresh.

I checked the printers settings, it has
IP Address: 10.1.21.20
Subnet mask: 255.255.254.0
Gateway: 10.1.20.1

all given out by DHCP.