OPNsense Forum

English Forums => 26.1 Series => Topic started by: trumee on February 07, 2026, 04:51:52 PM

Title: Rule migration breaks NAT/Port forwarding
Post by: trumee on February 07, 2026, 04:51:52 PM
Hello,

I have a dual WAN setup and i am trying to upgrade the router over the internet. I did a migration but my forwarded ports from WAN stopped working. I rolled back to the snapshot with the old rules.

I have a few questions,

Title: Re: Rule migration breaks NAT/Port forwarding
Post by: Bob.Dig on February 07, 2026, 06:28:37 PM
If I have to guess, your NAT worked but you had no allow rules for those? A reboot is not required.
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: nero355 on February 07, 2026, 08:39:32 PM
Quote from: trumee on February 07, 2026, 04:51:52 PMCan i keep using using old rules and continue making changes to opnsense without breaking it (e.g. suricata)? Or does the function now depend on New rules?
@franco has mentioned multiple times that there is no immediate need to migrate the Firewall Rules since the whole thing is "Work in Progress" for now and the moment that you will be more or less forced to do so is far, far, far away from now ;)
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: jysl on February 08, 2026, 06:16:06 AM
Same thing happen to me, it have to do with the reply to on multi wan that is not on the default gateway. I am not sure what the intend behavior is. But the below topic fixed for me

https://forum.opnsense.org/index.php?topic=50760.
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: Bob.Dig on February 08, 2026, 10:01:48 AM
Interesting, at least rules.debug shows no reply-to at all. Not sure if it was present there with an older config.
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: Bob.Dig on February 08, 2026, 10:29:36 AM
.
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: jysl on February 08, 2026, 10:54:14 AM
Here the setting that work only

https://imgur.com/9KoAz6a

I try setting the "Gateway" to the same gateway as the "reply to" and "reply to" none, but that didn't work
Also try the "Gatway" none, Checked the "Disable reply to" and "reply to" none, that also not work
Title: Re: Rule migration breaks NAT/Port forwarding
Post by: Bob.Dig on February 08, 2026, 10:56:37 AM
Yep, you only can set it in advanced mode of that rule, that makes sense. Why it is not the default anymore makes less sense to me.