OPNsense Forum

English Forums => 26.7 Series => Topic started by: klinebau on October 05, 2026, 02:32:44 PM

Title: SOLVED: DNAT Firewall Rule Not Working for IPv4+IPv6 After Server Change
Post by: klinebau on October 05, 2026, 02:32:44 PM
I have a dual-stack network and I have had the attached DNAT firewall rule in place for at least a year which allows me to access my internal applications from the internet.  This redirects/forwards the traffic to my internal nginx server.

I created a brand new server to address some security concerns I had with the previous server.  I updated the MAC address for the existing alias that I created for the old nginx server, but now I am not able to access my applications externally.  I think that opnsense creates firewall rules "behind the scenes" because I have specified Pass for the firewall rule item.  Because of this, I thought maybe it would work if I deleted and re-created the rule.  Unfortunately this did not solve the problem.

I am on 26.7.5 and migrated my old firewall rules to the new rules back in February.  Is this a regression introduced recently or am I doing something wrong?
Title: Re: DNAT Firewall Rule Not Working for IPv4+IPv6 After Server Change
Post by: Bob.Dig on October 05, 2026, 02:57:48 PM
If you use "pass", no IP-Blocklist will work.
Now to your question:
Go to Firewall > Diagnostics > Aliases and check if your Alias contains the right IP-addresses.
Title: Re: DNAT Firewall Rule Not Working for IPv4+IPv6 After Server Change
Post by: klinebau on October 05, 2026, 04:50:10 PM
I didn't think to look at the alias, but you are absolutely correct that this is where my problem lies.  Because I am using a MAC-based alias, it contains a whole bunch of other IP addresses that are no longer valid (dhcp addresses from before I set up the static host).  I did not realize that MAC-based alias would pull every IP that was ever associated with it.  It doesn't look like there is a way to remove the now invalid addresses.  For now, I have created host based alias and pointed it to two new aliases (one with ipv4 address and one with dynamic prefix for ipv6).  This works long term but with the cost of more alias names. I thought the whole idea of hostwatch was to be able to reduce this.  Isn't there any way to remove these now invalid IP addresses?
Title: Re: SOLVED - DNAT Firewall Rule Not Working for IPv4+IPv6 After Server Change
Post by: klinebau on October 05, 2026, 07:44:51 PM
So what I thought was an IPv6 problem with the DNAT rule was actually a more general failure of the rule.  Because there were multiple IP addresses for IPv4 in the alias (due to using the MAC address type with hostwatch), I believe that the supporting automatic pass rules did not get created at all.  Once the alias was set up to only have one IPv4 and one IPv6 it worked.  I will mark this issue as solved.
Title: Re: DNAT Firewall Rule Not Working for IPv4+IPv6 After Server Change
Post by: Bob.Dig on October 05, 2026, 08:20:53 PM
Yep, if the alias contains more than one address, there is a high likelihood that it will nat to the wrong IP.
Quote from: klinebau on October 05, 2026, 07:44:51 PMautomatic pass rules did not get created at all
Pass doesn't need any further rules.