OPNsense Forum

English Forums => 26.1, 26,4 Series => Topic started by: thebraz on January 23, 2026, 02:29:39 PM

Title: Destination NAT and Firewall Rules (new) after rules migration
Post by: thebraz on January 23, 2026, 02:29:39 PM
First of all...............upgrade to RC1 succeeded.
Applied all the patches mentioned in the other thread.
All the old rules migrated to new following the 5 steps of the Migration Assistant done.
OpenVPN Instance and port forwarding rules (now Destination NAT) all working (also the ones using Aliases).
Not tried the Shaper yet.

I'd have a question: in the OpenVPN section and in the WAN section of the Rules (new) I find rules that are already present in Destination NAT.
Furthemore if a rule is disabled in Destination NAT but enabled in the WAN section of Rules (new) the thing doesn't work till I enable it in Destination NAT.

I find confusing the apparent "duplication" of rules, could someone please help me clarifyng the function of the two section and why rules are present in both?

Thanks in advance
Title: Re: Destination NAT and Firewall Rules (new) after rules migration
Post by: keeka on January 23, 2026, 05:17:58 PM
One rule performs the NAT and the second permits the resulting traffic. With the previous system, it was a NAT port forward rule and a (potentially auto-managed) firewall rule.

I have not tried 26.1RC yet. But I have a feeling, with the way I've set up NAT and FW under 25.7, a straight forward migration will not be possible. For example, the change in the priority of floating rules on single interfaces and the lack of auto/associated firewall rules for port forwards.
Title: Re: Destination NAT and Firewall Rules (new) after rules migration
Post by: lmoore on May 04, 2026, 07:24:11 AM
Quote from: Yudre on May 04, 2026, 05:44:33 AMI've looked into this rule; it can disable the device if activated incorrectly.

What do you mean by this, what can be disabled?

What is the URL link about for "moto x3m", it wasn't in the post you quoted?
Title: Re: Destination NAT and Firewall Rules (new) after rules migration
Post by: nero355 on May 04, 2026, 04:26:28 PM
Quote from: lmoore on May 04, 2026, 07:24:11 AMWhat is the URL link about for "moto x3m", it wasn't in the post you quoted?
Lately there are more and more weird SPAMmers on the forum kicking old topics and posting URLs behind weird stuff like _____ at the end of a sentence and stuff like that... :(
Title: Re: Destination NAT and Firewall Rules (new) after rules migration
Post by: franco on May 05, 2026, 07:40:32 AM
Mod note: Deleted the spam account and related messages.
Title: Re: Destination NAT and Firewall Rules (new) after rules migration
Post by: lmoore on May 05, 2026, 11:04:47 AM
Quote from: franco on May 05, 2026, 07:40:32 AMMod note: Deleted the spam account and related messages.

Thanks Franco.

Cheers,

Larry.