1
23.7 Legacy Series / Help for debugging routing decision
« on: November 14, 2023, 06:12:35 am »
Hi,
I'm hunting for a strange phenomenon, but perhaps even my concept could be better....
In short:
There is a home network, with a usual homerouter. All clients use this router as uplink to the internet.
There are two instances of OPNsense. One offsite (Hetzner), the other one in the local area network. Both are linked together by wireguard.
The local OPNsense has two Gateways. First = local Router (upstream), second = offsite OPNsense (far Gateway)
On the local OPNsense there is this LAN rule: All from source "service", offsite Gateway.
At the service machine, there ist the local OPNsense = default GW.
Now the behavior looks like this:
initial traffic from service (for example "ping") is directed to the remote OPNsense
traffic from outside is answered via router:
like ping from service to domain.org: ---> far gateway
ping from domain.org to service: --> answered via router
For me there seem no rules, that might explain this behavior.
I'm missing something!
I'm hunting for a strange phenomenon, but perhaps even my concept could be better....
In short:
There is a home network, with a usual homerouter. All clients use this router as uplink to the internet.
There are two instances of OPNsense. One offsite (Hetzner), the other one in the local area network. Both are linked together by wireguard.
The local OPNsense has two Gateways. First = local Router (upstream), second = offsite OPNsense (far Gateway)
On the local OPNsense there is this LAN rule: All from source "service", offsite Gateway.
At the service machine, there ist the local OPNsense = default GW.
Now the behavior looks like this:
initial traffic from service (for example "ping") is directed to the remote OPNsense
traffic from outside is answered via router:
like ping from service to domain.org: ---> far gateway
ping from domain.org to service: --> answered via router
For me there seem no rules, that might explain this behavior.
I'm missing something!