Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Graylev

#1
General Discussion / Re: Issue migrating hardware
July 10, 2026, 11:31:44 PM
Hi, I finally fixed it. It turns out some of the firewall rules didnt get loaded properly when I imported the config.xml. You could see the rules in the GUI and they looked totally normal but some rules weren't functioning properly or only partially. On my guests vlan one computer that had a reserved IP via DHCP worked fine while other normal DHCP users on the same VLAN could ping external IP's but not operate on something like port 443. All I had to do was to duplicate the "Allow internet" rules and put them up higher than the old rules then everything returned to normal. It's a bit odd that rules go wrong when importing. I tried the wipe/rebuild/import-config twice and it did the same thing twice. I even exported the config twice. Which VLANs it effected did change between attempts but it was the same rules. Like you I would of thought it was something to do with the interface assignments.
#2
General Discussion / Issue migrating hardware
July 06, 2026, 06:05:06 PM
Hi, I used to run pfSense on a Protectli FW4B but I wanted to moved to OPNsense. I setup a VM in Proxmox and passed through two InteL NICS through to it. I got it all setup and working great. I've got a bunch of VLANS and DNS filters etc. Like I said it works great. I then wanted to move it to it's own dedicated hardware which is the protectli FW4B which also has intel nics and the same naming of igb0 for WAN and igb1 for LAN etc. My VM is on version 26.1.11. On the FW4B I installed the latest ISO I could get which is 26.1.6. I then restored a copy of the config.xml to it. I then unplugged the cables from the proxmox VM and plugged the FW4B into the same sockets. It powered up and I updated it to 26.1.11. Now is when it gets weird. No computer could browse the web but they could ping public IP's and do NSLOOKUP on any DNS name. In the firewall logs I get a lot of "Default deny / state violation rule". In my desperation I have some rules to stop people using other DNS than the ones hosted on the router. I disabled them and things sort of started working. My computer on my USERS VLAN worked but computers on the GUEST VLAN wouldnt work except for my daughters computer which is on a DHCP reservation. The guest VLAN only has one rule which is to allow internet access and thats it. It's very weird and confusing. It's a fresh install and just a copy of the config.xml which works fine elsewhere. Other than the router I also have two VLAN aware layer 2 switches. I'm out of ideas. The interfaces and vlans looks to be assigned to the correct physical interfaces. I think I've checked all the obvious stuff.