OPNsense Forum

Archive => 17.1 Legacy Series => Topic started by: cardins2u on March 15, 2017, 09:04:49 am

Title: Two OPNSense Router
Post by: cardins2u on March 15, 2017, 09:04:49 am
Hi franco,

I been trying to setup two OPNSense to route to each other and fail horrible.

OPNSense1
WAN: 10.2.10.10
Gateway: 10.2.10.1
LAN: 192.168.10.1/24

OPNSense2
WAN: 10.2.10.20
Gateway: 10.2.10.1
LAN: 192.168.20.1/24


I'm trying to interconnect OPNSense1 to OPNSense2. I created the gateways and static routes. I setup the firewall to allow access but it wont work. can you give me some help.

thank you
Title: Re: Two OPNSense Router
Post by: djGrrr on March 15, 2017, 03:56:34 pm
Have you disabled NAT on the WAN side of each OPNsense?
Title: Re: Two OPNSense Router
Post by: franco on March 15, 2017, 04:01:02 pm
Hi cardins2u,

djGrrr may be right: disable outbound NAT if you want to do native routing between the subnets.

Also make sure the "block private networks" option is off in the WAN interface settings.


Cheers,
Franco
Title: Re: Two OPNSense Router
Post by: cardins2u on March 16, 2017, 12:25:49 am
Cool that worked!

SO in your experience. Is it better to connect two subnet through the LAN or WAN interfaces?

I'm sure both need firewall settings to work. Which method would be preferable.
Title: Re: Two OPNSense Router
Post by: cardins2u on March 16, 2017, 01:01:30 am
@franco

Now that I got everything working and even ping across sub nets. I hit into another issue:


 second of all all though I can ping one of the server ips from OPNSense1 to OPNSense2 computer web server https://10.0.0.45:8443 (unifi controller). When I go to the address it wont load. I have to open up CMD and ping the 10.0.0.45 then reload https://10.0.0.45:8443 for the website to work.

do you know what I'm doing wrong?

Title: Re: Two OPNSense Router
Post by: franco on March 16, 2017, 08:20:06 am
Connecting through WAN or LAN (or OPT) is a matter of trust: WAN traditionally means no trust, LAN means unrestricted trust, OPT means partial trust. You certainly have less issues with moving the routing to LAN or OPT. OPT will probably fit best.

I'm not sure about the ping required to be able to access the server. It may be some type of state tracking getting in the way. It's probably related to the WAN-type routing. Did you disable NAT?


Cheers,
Franco
Title: Re: Two OPNSense Router
Post by: cardins2u on March 17, 2017, 03:11:56 am
yes I'm using LAN to lan right now. Everything works fine from OPNSENSE1 to 2.

but from 2 to 1 you have to ping to work.