OPNsense Forum

English Forums => 26.7 Series => Topic started by: devl_ish on September 25, 2026, 12:53:06 PM

Title: Action - Pass, Block, Reject - no "Match" - 26.7.4_1
Post by: devl_ish on September 25, 2026, 12:53:06 PM
Hi all - I'm following https://docs.opnsense.org/manual/how-tos/wireguard-s2s.html and stuck on Step 4b.

This calls for a Match rule for fragmentation prevention, but under the [Action] dropdown I only have the usual Pass, Block and Reject, even when showing advanced options. I've probably overlooked something stupid, what would hide the "Match" option?

Have just done an upgrade chain from 25.7 all the way to most current as of today, 26.7.4_1.
Title: Re: Action - Pass, Block, Reject - no "Match" - 26.7.4_1
Post by: franco on September 25, 2026, 12:59:02 PM
The documentation was updated too early on that subject, maybe we should revert it for now.  Sorry about that.


Cheers,
Franco
Title: Re: Action - Pass, Block, Reject - no "Match" - 26.7.4_1
Post by: devl_ish on September 25, 2026, 01:02:59 PM
Thanks, are you able to provide a lead (few sentences) on how to accomplish it in the interim, while formal docs are being updated?

Title: Re: Action - Pass, Block, Reject - no "Match" - 26.7.4_1
Post by: Wrigleys on September 25, 2026, 02:06:51 PM
Hi devl_ish

I assume you can use "pass" instead of "match" like documented under Rule normalization (https://docs.opnsense.org/manual/firewall_scrub.html):
QuoteSelect the Match action to apply normalization without deciding whether traffic is passed or blocked. A Pass rule can apply the same options while also allowing traffic. Match rules follow the normal firewall rule ordering; they are usually not quick so evaluation can continue after their options have been applied.

Stay safe,
Wrigleys
Title: Re: Action - Pass, Block, Reject - no "Match" - 26.7.4_1
Post by: Monviech (Cedrik) on September 25, 2026, 02:10:07 PM
No, the documentation is too new. It doesnt exist yet. But we fix that soon. So long you can look at the direct branch here:

https://github.com/opnsense/docs/blob/master/source/manual/how-tos/wireguard-client.rst