Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - slcoleman

#1
I have a Protectli 4 port running OPNSense where LAN1 (192.168.10.1/24) is a collection of I0T and other untrusted devices including a TP-Link AX5400 WiFi router (192.168.10.2/24) with an attached WiFi enabled printer (192.168.1.13). I am trying to print from trusted devices attached to the LAN2 interface (192.168.20.1/24) and nothing I have tried as far as firewall rules has worked. Ideally I want all LAN2 devices to be able to connect to any LAN1 device but not the other way around. There is obviously something I am missing here and I was hoping somebody might give me a clue what I need to do to make this happen.

I have logging for everything turned on but I don't see any indication as to where any specific rule denials are happening so I am thinking there might be a routing problem but don't know where in the OPNSense UI to enable something like that. It seems that the packets just don't go anywhere and no default denial rules are being triggered.

Is there a NAT problem on the TP-Link?
A missing interface route igb2->igb1 config?
What else am I possibly missing here?

WAN1 igb0 dhcp
LAN1 igb1 192.168.10.1/24 untrusted network
    Wifi device 192.16810.2
        WiFi printer at 192.168.1.13
LAN2 igb2 192.168.20.1/24 trusted network

thanks!
#2
I have a Protectli 4 port device (OPNsense 23.7.8_1-amd64) which I have been having issues with setting up the third LAN interface. I am currently getting the error:

"The DHCP Server is active on this interface and it can be used only with a static IP configuration. Please disable the DHCP Server service on this interface first, then change the interface configuration.",

but its not clear to me what exactly it is telling me I need to do. I had already deleted and recreated the interface once but its just not intuitive to me why the third interface is such a problem.

Basically I wanted three LAN's with 192.168.X.1 where X is different for each interface. Lan's 1 & 2 are working fine, but my third "administrative lan" just isn't cooperating. What am I doing wrong?

Identifier    opt2
Device    igb3
Description LAN3
IPv4 Configuration Type: Static IPv4 --> DHCP
Alias IPv4 address: 192.168.30.1 24