1
General Discussion / Re: LAN to OPT Rules?
« on: July 18, 2022, 12:46:13 pm »
Thanks for coming back.
I actually saw a similar response from you https://forum.opnsense.org/index.php?topic=29343.0 in my search but still didnjt have it right in my head.
I expected floating rules to apply to all, Interface LAN rules to apply to the LAN port and OPT interface rules to apply to the OPT port. Meaning OPT's ingress would be controlled by the union of floating and OPT interface rules only.
Given your response, and reading up on it some more, it appears an inbound rule on the LAN interface will also influence the OPT interface's ingress in this way. And I presume this is all working becasue the first match/precedence hits this LAN allow rule before the floating "default deny all" that covers OPT.
Perhaps it was the message "All incoming connections on this interface will be blocked until you add a pass rule" on the OPT2 interface rule page that threw me. I was expecting to have to add a "pass rule" on OPT.
Thanks for helping to confirm that I need the deny on LAN before the allow.
Have a nice day!
I actually saw a similar response from you https://forum.opnsense.org/index.php?topic=29343.0 in my search but still didnjt have it right in my head.
I expected floating rules to apply to all, Interface LAN rules to apply to the LAN port and OPT interface rules to apply to the OPT port. Meaning OPT's ingress would be controlled by the union of floating and OPT interface rules only.
Given your response, and reading up on it some more, it appears an inbound rule on the LAN interface will also influence the OPT interface's ingress in this way. And I presume this is all working becasue the first match/precedence hits this LAN allow rule before the floating "default deny all" that covers OPT.
Perhaps it was the message "All incoming connections on this interface will be blocked until you add a pass rule" on the OPT2 interface rule page that threw me. I was expecting to have to add a "pass rule" on OPT.
Thanks for helping to confirm that I need the deny on LAN before the allow.
Have a nice day!