1
General Discussion / Traversing 2 OPNsense to access the Internet is not working
« on: February 01, 2023, 04:56:09 pm »
Hello,
I usually use OPNsense as the only firewall, and it always works great & fine.
I wanted to increase the security of some file servers and put them behind a second OPNsense with firewall rules access.
The file servers behind the second OPNsense are reachable on both LAN, but they can't access the Internet.
Internet <-> OPNSense-1 <-> Main LAN (192.168.64.0/18) <-> OPNsense-2 <-> Secured LAN for File Servers (10.0.200.0/24)
Everything is working fine on the main LAN.
From the main LAN I can access the Secured LAN with the correct rules on OPNsense-2, so it works fine for me.
From the Secured LAN I can access the DNS servers on the main LAN.
But the File Servers on the Secured LAN are unable to access the Internet, they could need it for software update or licensing purpose. The main OPNSense should block this traffic.
This double LAN configuration is new to me...
I set a new gateway and a route on the main OPNsense-1 so he will know how to access 10.0.200.0/24 network, but it is not enough.
I suspect the first OPNsense to reject the network traffic for 10.0.200.0/24 network as his network is 192.168.64.0/18.
Do you have any clues ?
Thanks for your help,
Frédéric
I usually use OPNsense as the only firewall, and it always works great & fine.
I wanted to increase the security of some file servers and put them behind a second OPNsense with firewall rules access.
The file servers behind the second OPNsense are reachable on both LAN, but they can't access the Internet.
Internet <-> OPNSense-1 <-> Main LAN (192.168.64.0/18) <-> OPNsense-2 <-> Secured LAN for File Servers (10.0.200.0/24)
Everything is working fine on the main LAN.
From the main LAN I can access the Secured LAN with the correct rules on OPNsense-2, so it works fine for me.
From the Secured LAN I can access the DNS servers on the main LAN.
But the File Servers on the Secured LAN are unable to access the Internet, they could need it for software update or licensing purpose. The main OPNSense should block this traffic.
This double LAN configuration is new to me...
I set a new gateway and a route on the main OPNsense-1 so he will know how to access 10.0.200.0/24 network, but it is not enough.
I suspect the first OPNsense to reject the network traffic for 10.0.200.0/24 network as his network is 192.168.64.0/18.
Do you have any clues ?
Thanks for your help,
Frédéric