Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - TJL

#1
Disregard my previous message.
#2
25.7, 25.10 Series / Decoding "detailed rule info" screen
November 21, 2025, 05:48:34 PM
I am attempting to use a Watchguard SSL VPN client to connect remotely.  Clarification: I am using a computer behind a OPNsense firewall connecting to a computer behind a Watchguard firewall.  I didn't get a clean copy before I upgraded to 27.7.7_4.  The vpn client worked before the latest upgrade.  As I read the online instructions, I found the "rid" link on the "detailed rule info" screen should point to the rule of why my vpn connection is being blocked.  On a rule that "worked" (unrelated to this issue), I click on the rid link and it brings be Firewall:Rules:Advance screen.  I don't see why I go to this screen since there are no rules.  In my case, I click on the rid link, OPNsense opens a new window (like the one that works), but then immediately closes the window.
Here is a copy of the rule info screen:
__timestamp__   2025-11-20T21:54:22-06:00
ack   897488549
action    [block]
anchorname   
datalen   0
dir    [in]
dst   external IP
dsthostname   
dstport   443
ecn   
id   48471
interface   vtnet0
ipflags   DF
ipversion   4
label   Default deny / state violation rule
length   40
offset   0
protoname   tcp
protonum   6
reason   match
rid   02f4bab031b57d1e30553ce08e0ec131
rulenr   11
seq   431912277
src   internal IP
srchostname   
srcport   64022
status   2
subrulenr   
tcpflags   RA
tcpopts   
tos   0x0
ttl   128
urp   0

I think I sanitized the screenshot.  I first thought the rulenr was the rule number, but the rules that allow access show a value of 94, but I don't think I have that many rules, unless they are counting all rules for all interfaces.  As far as I can tell, going to other HTTPS sites are working as expected.

Will someone explain how to read this page to see what rule is causing the vpn to fail?

Thanks.
#3
Thanks for the assistance.  That didn't resolve my issue.  I might need to contact Watchguard and get guidance from them on which end is closing the connection.  Is there an "easy" way for a newbie to view detailed logs, other than in the gui?  I think I have checked all the "log" buttons on the gui and none are giving me any information.  Thanks!
#4
I don't seem to have an "Advanced features" under rules.  I have Floating, LAN, WAN, WireGuard (Group), WIreGuard_VPN, and my vlans.

A clarification/question: on the Firewall:Log view, I click on the far right button to show the rule that is blocking the VPN connection.  It is showing "rulenr 11" and when I count down on the rules, it appears to be the "virusprot" rule.
#5
New to OPNsense.  I just updated to 25.7.7_4.  I am attempting to use Watchguard SSL VPN to connect to a remote location.  This application worked without any issues on 25.7.6 and previous versions.  I attempted to use it after going to 25.7.7_4 and it fails every time.  OF COURSE, (lesson learned) I need to backup/get a snapshot before upgrading.  In the firewall logs, it appears to me it is showing the "virusprot overload table" rule is preventing me from connecting with VPN software.  Any suggestions?