1
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Pages: [1]
3
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 02:43:11 pm »
The rule is working as I would like, but something is not going exactly as I expect.
Let's go in steps:
- from the LAN hosts I block all ICMP packets to the OPT1 hosts.
- from the OPT1 hosts I block all ICMP packets to the hosts of LAN
- I apply the rules
- firewall -> diagnostics -> states -> actions -> reset state table
After that the rules work.
Unexpected behavior, however, when I want to re-enable ICMP packet transit.
- from the LAN hosts I allow all ICMP packets to the OPT1 hosts
- from the OPT1 hosts I allow all ICMP packets to the hosts of LAN.
- I apply the rules
At this point only one of the two works. I have now made 5 attempts as described and the ping works 4 times for LAN and 1 time for OPT1. Almost like it was a random thing.
Forgive me, this sounds strange, but it is happening.
Gianluca
Let's go in steps:
- from the LAN hosts I block all ICMP packets to the OPT1 hosts.
- from the OPT1 hosts I block all ICMP packets to the hosts of LAN
- I apply the rules
- firewall -> diagnostics -> states -> actions -> reset state table
After that the rules work.
Unexpected behavior, however, when I want to re-enable ICMP packet transit.
- from the LAN hosts I allow all ICMP packets to the OPT1 hosts
- from the OPT1 hosts I allow all ICMP packets to the hosts of LAN.
- I apply the rules
At this point only one of the two works. I have now made 5 attempts as described and the ping works 4 times for LAN and 1 time for OPT1. Almost like it was a random thing.
Forgive me, this sounds strange, but it is happening.
Gianluca
4
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 01:32:42 pm »P.S. sorry for messed up answer ^^'
Vilhonator, are you kidding? Thank you very much for all the information you are giving me!!!
I read the solution you proposed, but I think I need something simpler: I just want to disable ping from OPT1 network hosts to LAN hosts and vice versa. Or enable it when it should be necessary. Nothing more. And the rule I have set doesn't work and I would like to know why...
Thanks again for everything!
Gianluca
5
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 11:21:46 am »Seems that all is as should be.Okay, it looks like it's just a big misunderstanding, everything seems to be working properly. But but it is still possible from the OPT1 network to ping any PC in the LAN, but not vice versa. I would like to understand how to enable or disable pinging between hosts on the two networks at my convenience. The rule below should block ping from the OPT1 network to the LAN, and instead it continues to work. What am I doing wrong?
6
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 09:55:42 am »If ping doesn't work, despite disabling firewall on both computers, make sure OpnSense has all as should (no firewall rules blocking anything etc.)...
From what I have shown above it seems to be only a ping problem. As you can see, trying to connect to shared folders of the PCs on the other network, the PCs connect. At this point it really seems to be only a ping problem. For example, you can connect to an http server of one of the pc's on the other network:
7
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 09:52:15 am »How are you testing?I tried pinging or connecting to a shared folder. The PCs do not respond to the ping, but they connect to the shared folders.
Are you sure local firewalls (i.e.,windows firewall) aren't blocking at the device level, that's caught me a few times?The PCs' firewalls are temporarily disabled so as not to create interference.
8
22.7 Legacy Series / Re: Communication between two LANs
« on: December 29, 2022, 09:36:55 am »9
22.7 Legacy Series / Re: Communication between two LANs
« on: December 28, 2022, 09:10:58 pm »10
22.7 Legacy Series / Communication between two LANs
« on: December 28, 2022, 06:48:18 pm »
Hello everyone. I have a strange configuration (the customer told me how he wanted it) that i can't get to work as i would like.
He has a single gateway, a modem/router provided by the ISP, with internal address 192.168.64.1 and an OPNsense box with WAN interface 192.168.64.15.
This has two separate LAN interfaces, one with address 192.168.32.1 (LAN interface) and another with address 192.168.48.1 (OPT1 interface). For some strange reason, all PCs on the LAN must communicate with PCs on the OPT1 network and vice versa.
Right now, recently installed, OPNsense makes the PCs on theLAN OPT1 network communicate with those on the OPT1 LAN network, but those on the OPT1 LAN network do not communicate with those on the LAN OPT1 network. No further changes have been made.
It would be necessary to have the PCs on theOPT1 LAN network communicate with those on the LAN OPT1 network and, when desired, to be able to isolate the two networks quickly (which is strange, but so much is).
Can you help me with this?
Gianluca
He has a single gateway, a modem/router provided by the ISP, with internal address 192.168.64.1 and an OPNsense box with WAN interface 192.168.64.15.
This has two separate LAN interfaces, one with address 192.168.32.1 (LAN interface) and another with address 192.168.48.1 (OPT1 interface). For some strange reason, all PCs on the LAN must communicate with PCs on the OPT1 network and vice versa.
Right now, recently installed, OPNsense makes the PCs on the
It would be necessary to have the PCs on the
Can you help me with this?
Gianluca
Pages: [1]