<EDIT>
I took a look at my wiring today and I realized I had my computer (192.168.1.222) accidentally connected to both interfaces (LAN and VLANs) via a switch. That probably explains the asymmetric routing(!). But now that I removed my computer from the VLANs interface, my computer can't reach the truenas VM (192.168.3.248) at all.
My computer 192.168.1.222 can successfully ping 192.168.3.1.
The truenas VM 192.168.3.248 can successfully ping 192.168.1.1.
But 192.168.1.222 cannot talk to 192.168.3.248.
And whereas I was seeing block activity in the firewall live view before, now I'm not getting any, as though I broke the connection entirely. So, I don't even know where to go from here if the Opnsense firewall rules aren't to blame. I've also adjusted all of the networking-related knobs and dials within Proxmox that I am aware of to try and correct this.
At this point I believe this is a Proxmox VM configuration problem, and not anything with Opnsense. So I don't expect anyone here to help troubleshoot Proxmox. Unless anyone has any suggestions to try, I am very reluctantly moving everything back to bare metal this weekend.
Thank you again to everyone that has offered suggestions up to this point!
<EDIT 2>
For grins I just tried connecting both of the network ports into a switch and now things behave the way I would expect them to. My computer on 192.168.1.222 can reach the truenas gui at 192.168.3.248. I can also create firewall rules in Opnsense that pass or block traffic the way I would expect them to. I am obviously new to networking, so possibly I fundamentally misunderstand how routers help facilitate the movement of traffic between subnets.
Each of the physical network interfaces on my machine have their own separate multiport switch. I did that so I could segregate all of my devices--e.g. webcams would all connect to one switch (and hence one network interface), all MAIN LAN devices connect to another switch (and hence a second network interface), and so on. In that configuration I assumed all of the subnet traffic would have to pass THROUGH the router. That's how I previously had everything setup when I had Opnsense running on bare metal and it seemed to work just fine.
Now, it appears as though I need the two network interfaces plugged into the same switch to pass subnet traffic. I guess I'll have to just more reading, and I'll keep playing with it for the next few days and see if I can better understand what is happening.
I took a look at my wiring today and I realized I had my computer (192.168.1.222) accidentally connected to both interfaces (LAN and VLANs) via a switch. That probably explains the asymmetric routing(!). But now that I removed my computer from the VLANs interface, my computer can't reach the truenas VM (192.168.3.248) at all.
My computer 192.168.1.222 can successfully ping 192.168.3.1.
The truenas VM 192.168.3.248 can successfully ping 192.168.1.1.
But 192.168.1.222 cannot talk to 192.168.3.248.
And whereas I was seeing block activity in the firewall live view before, now I'm not getting any, as though I broke the connection entirely. So, I don't even know where to go from here if the Opnsense firewall rules aren't to blame. I've also adjusted all of the networking-related knobs and dials within Proxmox that I am aware of to try and correct this.
At this point I believe this is a Proxmox VM configuration problem, and not anything with Opnsense. So I don't expect anyone here to help troubleshoot Proxmox. Unless anyone has any suggestions to try, I am very reluctantly moving everything back to bare metal this weekend.
Thank you again to everyone that has offered suggestions up to this point!
<EDIT 2>
For grins I just tried connecting both of the network ports into a switch and now things behave the way I would expect them to. My computer on 192.168.1.222 can reach the truenas gui at 192.168.3.248. I can also create firewall rules in Opnsense that pass or block traffic the way I would expect them to. I am obviously new to networking, so possibly I fundamentally misunderstand how routers help facilitate the movement of traffic between subnets.
Each of the physical network interfaces on my machine have their own separate multiport switch. I did that so I could segregate all of my devices--e.g. webcams would all connect to one switch (and hence one network interface), all MAIN LAN devices connect to another switch (and hence a second network interface), and so on. In that configuration I assumed all of the subnet traffic would have to pass THROUGH the router. That's how I previously had everything setup when I had Opnsense running on bare metal and it seemed to work just fine.
Now, it appears as though I need the two network interfaces plugged into the same switch to pass subnet traffic. I guess I'll have to just more reading, and I'll keep playing with it for the next few days and see if I can better understand what is happening.
"

