1
21.7 Legacy Series / Re: FW between 2 private subnets
« on: November 13, 2021, 02:46:52 am »You can keep repeating the same thing, but it is still not true.
Even the GUI tells you are wrong - have a look at the bottom of the Rules page for each interface: “Everything that is not explicitly passed is blocked by default.”
Yes, with the default LAN “allow to any” rules, anything coming into the LAN interface will be allowed anywhere, including to the DMZ subnet. But the reverse does not apply (other than of course stateful replies to incoming LAN traffic).
Outbound NAT has nothing to do with it. The automatic Floating rules block everything into an interface by default (with limited exceptions), and allow everything out of an interface by default (coz OPNsense’s default policy is to filter inbound).
So do you have suggestions for the User who posted why not help them?