OPNsense Forum

English Forums => Virtual private networks => Topic started by: opkky on February 16, 2026, 01:00:31 PM

Title: ZeroTier Road Warrior setup on 26.01
Post by: opkky on February 16, 2026, 01:00:31 PM
Hello Guys.

I am setting up remote access to my home network with the help of ZeroTier and OPNsense v26.01
At the end I need to get access to my home network behind OPNsense.

For some reason I can access only OPNsense router via ZeroTier overlay but not the LAN network behind the bridge.
I have a computer with 4 GE ports. The first is WAN and the rest 3 are bridged in to Bridge LAN

Firewall from ZeroTier interface to bridge lan is open
(https://i.postimg.cc/zBNMs3fg/Screenshot-2026-02-16-at-12-52-03.png) (https://postimg.cc/Z9fV3bpb)

and

(https://i.postimg.cc/63H0MQ2b/Screenshot-2026-02-16-at-12-51-45.png) (https://postimg.cc/N9HmMBxR)

Any ideas what is going wrong here?
Title: Re: ZeroTier Road Warrior setup on 26.01
Post by: opkky on February 18, 2026, 02:50:44 PM
Case is closed.

The problem was not related to ZeroTier. It was because I used lanbridge interface on the device.
It require additional floating outgoing firewall rule to allow traffic from bridge to LAN.

Now all works fine.
Title: Re: ZeroTier Road Warrior setup on 26.01
Post by: Patrick M. Hausen on February 18, 2026, 02:53:35 PM
Quote from: opkky on February 18, 2026, 02:50:44 PMIt was because I used lanbridge interface on the device.
It require additional floating firewall rule to allow traffic from bridge to LAN.

This should not be necessary.

Did you

- assign "LAN" to the bridge interface?
- add the two mandatory tunables for a LAN bridge?

Documentation, step #6.

https://docs.opnsense.org/manual/how-tos/lan_bridge.html#lan-bridge
Title: Re: ZeroTier Road Warrior setup on 26.01
Post by: opkky on February 18, 2026, 04:00:40 PM
All steps related to bridge creation were done as said in documentation, including step 6.

This is a new device install. There is nothing special is needed, except remote access to the network.

I noticed that even if I ssh directly to the device and then in cli ping from Bridge interface hosts from LAN, it was not working.
And after applying floating firewall rule, it started to work as PF was blocking access.

Ans as a result access to LAN hosts via ZeroTier also started to work