well, after way too much time spent on this I am giving up, for now at least. I don't absolutely need this dual home VM there but I hate not getting to the bottom of an issue like this.
It must be asymmetric routing related as some (?) return traffic "comes back" via the opnsense interface from other network devices despite staying in the same local VLAN. I put "come back" in quotes because it's more like "seen by opnsense" which causes all these drop logs, but the packets do arrive.
when I remove the VM's interface in that VLAN, causing all traffic to have to go through opnsense, no more state violations.
I tested everything I could think of, but the Linux bridge setup in proxmox is pretty simple and checks out and the interfaces in opnsense also show what I would expect. yet..
I might come back to this, and if anyone has theories I'm interested. Thanks!
It must be asymmetric routing related as some (?) return traffic "comes back" via the opnsense interface from other network devices despite staying in the same local VLAN. I put "come back" in quotes because it's more like "seen by opnsense" which causes all these drop logs, but the packets do arrive.
when I remove the VM's interface in that VLAN, causing all traffic to have to go through opnsense, no more state violations.
I tested everything I could think of, but the Linux bridge setup in proxmox is pretty simple and checks out and the interfaces in opnsense also show what I would expect. yet..
I might come back to this, and if anyone has theories I'm interested. Thanks!
"