Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Jimbo218297

#1
26.7 Series / State limits and the virusprot alias
August 29, 2026, 07:12:47 PM
I noticed that you can create state limits using the virusprot alias in firewall rules to help prevent against potential abuse or attacks but I'm a bit confused about the set up process.

In the advanced setting on firewall rules I'm assuming you enter the maximum source connections then below that you set the virusprot alias as the overload table option. But I've noticed that all my IP type aliases are also listed as options for the overload table?

What I'm confused about is what the virusprot alias actually is? It's listed as dynamic when viewed with the list of aliases I've created myself.

Also what would happen if I put an IP type alias I've created as an option for the overload table when creating a state limit? Would it limit maximum states only for those source networks/IPs?

I see there is also an automatically generated rate limit rule that is created when the checkbox 'Disable rate limit rule' is unchecked (default) which also uses the virusprot alias as the source address.

Thanks in advance for any help as I'm by no means an expert. I've recently moved from pfSense and it's great to be able to support the project directly so I've been donating €10/month to show my appreciation.
#2
I installed a OPNsense onto a Protectli Vault about 6 weeks ago and I've slowly been configuring the firewall over the weekends since I'm moving from an pfSense build I've been using for about 8 years. I have a strange situation where I'm able to ping from any of my lan interface addresses out to the public internet using the system diagnostics ping tool but I'm unable to ping out from any device on the local networks. I'm have a firewall rule allowing any traffic in from any source to any destination on my local network currently while I'm trying to figure out what's going on. I have manual outbound NAT rules in place for both my WAN and VPN interfaces with an alias containing all my local network addresses as the source address. I'm currently configuring it behind another firewall so the WAN ip address is a private ip address. I'm able to ping any of my local network addresses from any devices that are on any of my local networks but I'm not able to ping my WAN gateway ip address or my WireGuard gateway ip address. The WireGuard gateway is up and running and I'm able to get the system to check for updates, ping and traceroute using the WireGuard interface so I know there's no issues with NAT on either the WAN or WireGuard gateways. I am using the WireGuard gateway as my default gateway as I did in pfSense using a default route that makes sure the WireGuard gateway always connects to the remote server using the WAN gateway so as not to create a chicken and egg situation. Any suggestions will be helpful as I've pretty much finished tinkering with configuration and I've spent the last three weekends trying to figure out why I can't get it working.