Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - BoerBart

#1
Quote from: nero355 on Today at 07:08:11 PMPost your network setup and all the Firewall Rules for the LAN Interface.

Is the Mini PC a Single NIC model or Dual/Quad NIC ?


And in general : The more info you provide, the less guessing we all have to do! ;)

Sure - I'll do my best in providing what's needed; I don't have much experience networking-wise, so it's a bit of guessing what is needed.

Network setup
Modem of provider --> TP-Link archer AX50 (bridge mode) --> TP-Link TL-SG108E switch --> single NIC Mini PC.

Switch port layout
Port 1 is TP-Link archer AX50
Port 2 is Single NIC Mini PC #1
Port 2 is Single NIC Mini PC #2

Switch VLAN (802.1Q) configuration
VLAN ID     VLAN Name     Member Ports     Tagged Ports     Untagged Ports
1     Default     1-8    1-8   
5     Redacted    2-3    2-3       
10    Redacted    2-3    2-3       
15    Redacted    2-3    2-3       
20    Redacted    2-3    2-3       
25    Redacted    2-3    2-3       
30    Redacted    2-3    2-3       
50    Redacted    2-3    2-3       
80    Redacted    2-3    2-3       
101   Redacted    2-3    2-3       
110   Redacted    2-3    2-3       
111   Redacted    2-3    2-3       

All firewall rules that are either directly on the LAN interface, or the rule itself contains multiple interfaces, including LAN, are exported to a csv file that can be downloaded here:
https://filebin.net/aer3hx75u8wj72il

If more information is needed - happy to deliver more. I've restarted all devices/networking equipment earlier today without luck.
#2
I've been using OPNsense for about two years now, never had any issue, until a few days back. I've set up a few VLANs in OPNsense that are all functioning properly, but I'm having issues on the LAN interface since recently. My idea is that the issue started either because of:

- An OPNsense update;
- Using the rule migration tool.

OPNsense version: 26.7.4_1
Architecture: amd64
Updated on: Sun Sep 20 15:14:10 UTC 2026

I'm running two Peladn N95 nodes in Proxmox, both are fully up-to-date as well.
Firmware version of the Peladn network devices: rtl8168h-2_0.0.2 02/26/15

The two peladn nodes, my PC, phone and such are all on the same LAN interface. OPNsense is running on a VM in the Proxmox cluster, i've got quite a few other containers/VMs running, each in several VLANs. Two days ago (after running the migration tool), I noticed that the internet on my phone got spotty, and today i've noticed it on my PC. When looking at the firewall logs, I noticed that (randomly to me) connections are being dropped, though not all. A page or Whatsapp message sometimes loads/gets delivered, and the next time it keeps loading/sending. Here are the output details for one of them of the Live View:
 
__timestamp__ 2026-09-29T15:48:11
ack 3901492930
action [block]
anchorname
datalen 39
dir [in]
dst 34.54.185.247
dsthostname
dstport 443
ecn
id 13033
interface vtnet0
ipflags DF
ipversion 4
label Default deny / state violation rule
length 91
offset 0
protoname tcp
protonum 6
reason match
rid 02f4bab031b57d1e30553ce08e0ec131
rulenr 13
seq 3881579953:3881579992
src 192.168.1.225
srchostname
srcport 40708
status 2
subrulenr
tcpflags PA
tcpopts
tos 0x0
ttl 64
urp 63

When looking at Firewall -> Diagnostics -> Statistics -> Rules, my assumption that this is rule 13:
@13 block drop in log inet all label "02f4bab031b57d1e30553ce08e0ec131"

    15
    :
     
    59
    :
     25 2026
    evaluations
    :
     11538
    packets
    :
     1700
    bytes
    :
     171359
    states
    :
     0
    nodes
    :
     0
    limit
    :
     0
    nat/rdr
    :
     0
    route
    :
     0
    inserted
    :
     uid 0 pid 0
    state_creations
    :
     0
    time
    :
     tue sep 29

This issue only happens on the LAN interface, all other interfaces are running just fine. I can't seem to figure out what I can do to solve this. I do not have any other rules that block traffic on the LAN interface.