OPNsense Forum

English Forums => General Discussion => Topic started by: Valkyre on April 15, 2020, 11:31:29 pm

Title: Help with firewall rules between vlan (Screenshots fixed)
Post by: Valkyre on April 15, 2020, 11:31:29 pm
Hey Guys,
I am in the middle of migrating from my virtual pfsense to a qotom opnsense box but i can't figure out the following:

I have my vlan 0 traffic as LAN
and vlan20 for my infra traffic which among other things hosts my vmware hosts.

When i connect to a VMware remote console from the lan network this is unworkable since it freezes every few seconds for a couple of seconds.
192.168.1.240 is my LAN desktop
192.168.20.90 is my VMware ESX host which hosts the VM and i need to go through this host to access the console view.

screenshot of the firewall log
https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/JNtQT3SdwKkKjc8?x=1912&y=714&a=true&file=blockedtraffic.PNG&scalingup=0 (https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/JNtQT3SdwKkKjc8?x=1912&y=714&a=true&file=blockedtraffic.PNG&scalingup=0)

and the details of the blocked rule
https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/3T4XjBWk7fMCbSb?x=1912&y=714&a=true&file=detailedrules.PNG&scalingup=0 (https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/3T4XjBWk7fMCbSb?x=1912&y=714&a=true&file=detailedrules.PNG&scalingup=0)

As a test i created the red underlined top rule i would say all traffic is allowed and i can't figure out why the traffic is being blocked ?
The inverse rules a little lower shouldn't be hit right?
https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/GwHnZSFABBgpESN?x=1912&y=714&a=true&file=toprule.PNG&scalingup=0 (https://wolk.imanbakker.nl/apps/files_sharing/publicpreview/GwHnZSFABBgpESN?x=1912&y=714&a=true&file=toprule.PNG&scalingup=0)


This problem is bugging me for a long time, and i thought it had to do with my firewall being a virtual one, but apparently it must be in the rules somewhere ;(

many thanks for any insight!


edit: ok i really messed up the screenshots... now i think they should work