OPNsense Forum

English Forums => General Discussion => Topic started by: PCG on June 05, 2024, 09:25:12 AM

Title: Automatic firewall rule that prevents my LAN
Post by: PCG on June 05, 2024, 09:25:12 AM

Good morning,
I am encountering a difficulty.
I have a rule in place that allows my IPv4 LAN to communicate with my WAN address:
Protocol IPv4 source "ip of my lan" port "any" destination "wan address" port "any" gateway "default"

Despite this rule, I have the default rule that blocks me:
   Source "IPlan:54941" destination "8.8.4.4:53" protocol "udp" label "Default deny / state violation rule"

I can't override the automatic rule.
Can you help me please ?
Title: Re: Automatic firewall rule that prevents my LAN
Post by: Patrick M. Hausen on June 05, 2024, 09:44:31 AM
You need to change "IP of your LAN" to "LAN net" - that is a predefined alias.
Title: Re: Automatic firewall rule that prevents my LAN
Post by: PCG on June 05, 2024, 10:00:06 AM

Thanks for your feedback.
Despite this configuration with the alias, the rejection remains the same..
Title: Re: Automatic firewall rule that prevents my LAN
Post by: mooh on June 05, 2024, 12:54:49 PM
You don't say what "WAN adresse" is. I guess it doesn't match 8.8.4.4. Maybe you can tell us what this rule is supposed to achieve. Then, the forum may be able to help better.
Title: Re: Automatic firewall rule that prevents my LAN
Post by: Patrick M. Hausen on June 05, 2024, 06:49:38 PM
This rule now permits your LAN network to communicate with the WAN address - which is the single address of your firewall on the WAN interface. I thought that's what you want?

Do you want your LAN network to be able to communicate with "the Internet" which is connected to your WAN? That is of course "any", because "the Internet" contains all possible addresses (with few exceptions).