Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - abenaou

#1
Quote from: Patrick M. Hausen on December 07, 2025, 09:38:51 PMIf the DHCP server in LAN98 sends a default gateway that is the cause for your static route. Don't use DHCP or any dynamic configuration for anything but WAN.
This was indeed the solution to the problem, thank you so much.
#2
Quote from: Patrick M. Hausen on December 07, 2025, 12:54:23 AMInterfaces > LAN - is there a gateway set?
Here is what my LAN interface looks like (didn't set anything there) as well as the second lan98 interface that connects through dhcp:

Screenshot attached
#3
As a workaround I emplemented a cron to delete that route, I really don't know where to look for anymore :

* * * * * /sbin/route delete -host 10.99.200.180
#4
Quote from: Patrick M. Hausen on December 06, 2025, 04:43:15 PMInterface configuration for LAN - did you set a gateway there? Don't.

If you need static routes pointing to that other firewall, add it as a gateway in System > Gateways and add the static routes as necessary.
Thanks, I checked, there are no routes configured in both of my LAN interfaces :
system -> routing -> configuration = empty

This is what makes it confusing, is that I don't have any static routes on both firewalls, just the gateways whith different priorities (1 for IPv6 / 2 IPv4 / 256 for the LAN98 interface)
#5
Quote from: Patrick M. Hausen on December 05, 2025, 08:54:18 PMUGHS - that route is static. It's configured somewhere. Do you have configured a gateway on vlan0.6? Remove that.
Thanks for your answer.
Where should I look? I checked :
System -> Routes -> configuration
And there is no such a route, in fact the page is empty.
I even downloaded the configuration file and did and nothing came up:
grep -rni 10.99.200.180 myroute-20251206083945.xml
Where should I check?

Thanks
#6
Here is more details about the route :

Proto   Destination   Gateway   Flags   MTU   Netif   Netif (name)
ipv4   10.99.200.0/24   link#14   U   1500   Vlan0.2   LAN
ipv4   10.99.200.1   Link#10   UHS   16384   lo0   loopback
ipv4   10.99.200.180   10.99.200.1   UGHS   1500   Vlan0.6   LAN98

The unwanted route is 10.99.200.180 being sent to 10.98.200.1 which is another firewall, the traffic ends up being blocked and rejected, making the server 10.99.200.180 isolated from the internet.

Do you have any ideas?

Thanks
#7
Hi all,

I have 2 opnsense firewalls, both running 25.7.8 and to each their vlan.
They're both interconnected by their LAN interfaces, in case WAN1 fails the traffic goes through the gateway of WAN2.
No the issue I have is that a route shows up on its own, I didn't create it, and when I delete it keeps coming back bringing my server down :
The faulty route is 10.99.200.180 being sent to 10.98.200.1 which goes through WAN2, I didn't add it and even when I delete it, it keeps coming back.
Can you please help?

Thanks
#8
This has been solved in the latest release :
OPNsense 25.7.1_1-amd64

Thanks for the devs and the forum participants.
#9
Quote from: Monviech (Cedrik) on July 31, 2025, 09:08:31 PMhttps://forum.opnsense.org/index.php?topic=48256.0
Thanks for replying back, I guess I am just going to wait for it be fixed in the upcoming version, I want to keep a consistent build.
#10
I upgraded to the 25.7.1 and I still don't see the individual wake up button, I used a private browser window but still the same issue.

Is this a know problem?
#11
I solved the issue, it turned out that there was a route that I didn't create, since I have 2 opnsense routers, each with its own WAN, the rule forwarded the traffic to the second router (10.98.200.1), then the router forwarded back the traffic to the first router (10.99.200.1) which resulted in traffic being denied.
Once I deleted the route the traffic was forwarded correctly.
#12
Any idea what might be the issue or things I need to check?

Thanks
#13
Hi everyone,

I am running a vm opnsense with nic pass through, one day a host took the same IP address of my freebsd samba directory server, so naturally it lost all connections.

I resolved the IP configuration, but now opnsense blocks any traffic going from that host 10.99.200.180 and going to the internet, it even blocks ICMP from 10.99.200.180 to 10.99.200.1

I tried everything, from reboot to clearing the firewall states, I even added an allow all for that host but nothing makes a difference :

LAN99 2024-08-06T13:55:26-06:00 8.8.8.8:53 10.99.200.180:50412 udp Default deny / state violation rule
LAN99 2024-08-06T13:55:26-06:00 8.8.8.8:53 10.99.200.180:23150 udp Default deny / state violation rule
LAN99 2024-08-06T13:55:21-06:00 8.8.8.8:53 10.99.200.180:61680 udp Default deny / state violation rule
LAN99 2024-08-06T13:55:16-06:00 8.8.8.8:53 10.99.200.180:41532 udp Default deny / state violation rule
LAN99 2024-08-06T13:55:11-06:00 8.8.8.8:53 10.99.200.180:37913 udp Default deny / state violation rule
LAN99 2024-08-06T13:54:41-06:00 8.8.8.8:53 10.99.200.180:40618 udp Default deny / state violation rule
LAN99 2024-08-06T13:54:40-06:00 8.8.8.8:53 10.99.200.180:51398 udp Default deny / state violation rule
LAN99 2024-08-06T13:54:36-06:00 8.8.8.8:53 10.99.200.180:55795 udp Default deny / state violation rule
LAN99 2024-08-06T13:54:34-06:00 8.8.8.8:53 10.99.200.180:30997 udp Default deny / state violation rule


Oddly traffic coming from another vlan is transmitted to the host :

LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:24881 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:56589 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:12203 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:64138 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:3546 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:29368 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:4573 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:55236 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:54747 10.99.200.180:53 udp let out anything from firewall host itself (force gw)
LAN98 2024-08-06T13:55:45-06:00 10.98.200.20:32114 10.99.200.180:53 udp let out anything from firewall host itself (force gw)


Can you please help?

Thanks