I like the notion of open source.
OPNSENSE is beautifully crafted.
BUT .......
I hate the fact that most of the traffic on my OPNSENSE firewall gets passed by the rule that says "let everything out from the firewall itself".
A firewall should only pass traffic that is explicity approved otherwise the firewall is really acting more like a router.
So I downloaded the free Sophos firewall and had it up and running in 5 minutes.
The default rule is a last matching (non-quick) rule so you could just have created your own quick matching block rule at the end.
Anyway have fun with your Sophos firewall, no shame in using something different.
Yup. Good luck with Sophos. We hope it serves you well for years to come.
How does "Firewall->Settings->Advanced->Disable force gateway" fit in here (or not)?
The bigger question is what the problem with the rule is and why non-transit traffic matters to the OP when he talks about firewalls. It's not a very interesting question, though.
Cheers,
Franco
The usual: READ THIS FIRST (https://forum.opnsense.org/index.php?topic=42985.0), points 16 and 24.
Heck, I was confused by it, too. Folks here straightened me out. Not much more to it.