Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sammasid

#1
The firewall rule
#2
First of All I am very ThankFull to Opnsense Team for such an amazing piece of firewall. Well I am new to it.
I have setup my OPNsense as VM inside Proxmox server at home with vtnet0 as WAN, vtnet1 as LAN and vtnet2 as VLAN . I am having 4 physical NICs.
  • ensp1so as main NIC attached to my proxmox server. Internet connection coming directly from my router Lan port 1 into this NIC
  • enx00e04c68011b as a WAN NIC for OPNsense VM separately. Internet connection coming out from my router Lan port 2 in this NIC
  • enx00e04c680647 as a LAN NIC for OPNsense VM. I attached my TP-Link wifi router to this NIC as bridge network so that I can connect my laptop to this wifi and access my opnsense GUI. Also I can surf internet and few mobile devices are connected to this wifi
  • enxa0cec80cf6dc as a VLAN NIC. Not attach/ used yet for anything. No connection cable in it. Spare totally
Having the above I have a default Vmbr0 Bridge on ensp1so. It has 192.168.100.201/24 and a gateway of 192.168.100.1. This makes me able to open my proxmox GUI over my laptop. Having said that whenever I am connected to main router wifi, I can access my proxmox GUI. But I am also able to access it whenever I am connected to TP-Link wifi router as mentioned above num 3 point

Coming over to Linux Bridges side
  • vmbr1 brigde Port enx00e04c68011b (WAN NIC for OPNsense VM separately as mentioned above)
  • vmbr2 bridge Port enx00e04c680647 (LAN NIC for OPNsense VM as mentioned above)
  • vmbr3 bridge Port enxa0cec80cf6dc (VLAN NIC as mentioned above)

So for so I am good. If I attach vmbr2 which is LAN NIC for Opnsense to any other VMs network in my proxmox, it gets IP address from my Opnsense LAN IP Range. These mean things are working. (keep in mind, this NIC is also plugged into my TP-Link router. Only when I am connected to this, I can ssh my VMs)

Now coming towards the HELP I need - THE VLANS side

On vmbr2, I have created 2 Vlans
  • vmbr2.10
  • vmbr2.20

In OPNsense GUI Interface>Devices>VLAN I have add a vlan with tag 20 on parent vtnet1 which is a LAN.
In OPNsense GUI Interfaces>Assignment I have assigned the device to interface and named it Cloud than enable the interface and configure a static IPV4 192.168.20.1/24.
In OPNsense GUI Services>ISC DHCPV4>[Cloud], I enable DHCP server on Cloud interface and set Range 192.168.20.100 to 192.168.20.150
In OPNsense GUI Firewall>Rules>Cloud, I created a rule Pass, interface:cloud, Direction:in, TCP/IP Version:IPV4, Protocol:any, Source:any, Destination:any
for test purpose.
I than add tag 20 to VM with vmbr2 in proxmox. I found that no IP address is assigned and I cannot get internet access.


NOTE to CONSIDER
My motivation is to get a VLAN on my LAN bridge vmbr2 to which I can attach any other VM in future. Need help KINDLY.

Regard's
Sam