OPNsense Forum

English Forums => 25.1, 25.4 Production Series => Topic started by: HighFive on June 25, 2025, 11:36:19 PM

Title: "Traffic showing as "let out anything from firewall host itself" - NAT/fw Q?
Post by: HighFive on June 25, 2025, 11:36:19 PM
rule order question

Just started with OPNsense and have a question about firewall rule matching and logging.

Setup:


Issue/Question:
Most (if not all) outbound traffic from internal LAN clients is matching the automatic rule "let out anything from firewall host itself (force gw)" or "let out anything from firewall host itself". In the live log view, source address always shows the WAN IP even though I know the traffic originates from LAN clients.

I understand NAT rules are processed before firewall rules, but want to confirm this behavior is normal. Since outbound traffic passes by default anyway, it would be preferable to see the internal LAN IPs as source rather than the OPNsense IP address in the logs.

Questions:



Current status:


Any guidance on whether this is expected behavior or if I need to adjust my configuration would be appreciated.
Title: Re: "Traffic showing as "let out anything from firewall host itself" - NAT/fw Q?
Post by: patient0 on June 26, 2025, 06:40:50 AM
The standard, automatically created 'Default LAN allow' firewall rules does not log, that is why you don't see that traffic. If you enable it - and keep the default logging for blocked and passed packets - you will see two matching rules, one on the LAN interface and one on the WAN interface.