Quote from: nero355 on July 23, 2026, 04:02:12 PMQuote from: Warbreaker on July 22, 2026, 07:43:52 PMIMHO you found a bug, because why would you need both of them when uPnP does more than a Source NAT Rule with Strict-port Enabled does : It completely opens the port like a Port Forward a.k.a. Destination NAT Rule would :)Are you talking about Firewall Rules or NAT Rules ?!
I'm sort of new to OPNSense, I started using OPNSense somewhere around 26.1.x, in my new installation back then I migrated to the new rules set because of a message I read that legacy would go away, so maybe the bug I found was with the new rules set?
IMHO the migration from Firewall Rules (Legacy) to Firewall Rules [New] that was more or less the thing to do before upgrading from 26.1.x to 26.7.x to avoid issues and should not have any affect to this whole story.
However the migration from Outbound NAT Rules to Source NAT Rules that's now a thing during the 26.7.x Release and should IMHO be done before the upgrade to 27.1.x in January 2027 could indeed have some kind of bug related to Strict-port since it was added a bit later after the whole new Source NAT section was added to 26.1.x :)
Sorry I missed your question, let me list in order the things I did in 26.1:
- I migrated from legacy to the new firewall rules set when I installed 26.1
- When I installed uPnP I converted the NAT mode from automatic to hybrid
- I did not do anything related to firewall or NAT when I migrated to 26.7, no conversion (it was already converted), but my destination NAT firewall rules seem to work, I have a DNS and time server redirect that are still working from 26.1, but they were created after I migrated to the new firewall rules set
- Once I moved to 26.7 a bit later I added the source NAT rule so uPnP would work again so now everything is working, only the "?" source IP bug on the uPnP when listing the current mappings
"