OPNsense Forum

English Forums => General Discussion => Topic started by: chrisb on June 18, 2026, 12:53:50 PM

Title: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: chrisb on June 18, 2026, 12:53:50 PM
Hi All,

I have configured a new OPNsense box, with the above rule blocking all my traffic to internal hosts.
Firewall logs show all traffic destined for the internal host blocked.
I am unable to elevate my custom rule before the default deny rule - or I do not know how to do it.

I am unable to find any documentation to assist me.

Please advise.

Thank you.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: Patrick M. Hausen on June 18, 2026, 12:58:38 PM
Please show your custom rule details.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: chrisb on June 18, 2026, 01:29:11 PM
Please see here.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: Bob.Dig on June 18, 2026, 06:45:28 PM
Why do you set a source port... Ok, the WebUI could be a little more specific about that.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: Monviech (Cedrik) on June 18, 2026, 08:23:03 PM
Quote from: Bob.Dig on June 18, 2026, 06:45:28 PMWhy do you set a source port... Ok, the WebUI could be a little more specific about that.

The Webgui is specific here, its "Source (Advanced)" and collapsed by default. If that doesnt imply enough I cannot help investigative users.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: chrisb on June 23, 2026, 12:25:48 PM
I resorted to installing and configuring v25.7.11 - working with no issues.
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: Bob.Dig on June 23, 2026, 12:28:32 PM
Why? Did you make your rule right this time?
Title: Re: v26.1.10 Default deny / state violation rule block DNAT rules
Post by: chrisb on June 23, 2026, 12:31:11 PM
I configured my rules the same way.