OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of johnw230873 »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - johnw230873

Pages: [1]
1
General Discussion / [Answered] Firewall rules, Have I read this wrong or just doing it the hard way
« on: July 31, 2019, 09:22:50 pm »
Hi, from the reading I have done with testing to confirm, for me when I have Guest network and DMZ network it seems the only way to truly lock them down is to use floating rules.

For ease or reading in this "Interface" is referring to a logical interfaces setup inside opnsense, "Network port" then I referring to the physical network port (or logical if opnsense is virtualised)  coming into the firewall from the outside world.

From what I can tell, the normal firewall rules only work on traffic received from the network port and not coming from the interfaces (e.g. intervlan communication).

If I have this correct then when creating a DMZ I prefer to be able to set this up once and know that no traffic can get to this network or come out of this network once it has been set.

With the standard rules on the DMZ interface I can make sure no traffic can go to any other network but I can't stop other traffic coming in, this needs to be done on each other interface.

This means that when ever a new interface is created I need to remember all the networks that need to be isolated and create new rules for them to make sure they stay isolated.

Have I got this correct ?

For now I've flicked over to floating rules for these networks and basically said any traffic going to this network not from this network is blocked.

Is this the best way or I'm I looking at this old school?

2
General Discussion / Port forward using extrenal DNS from the LAN
« on: December 07, 2018, 05:34:42 am »
Hi, I have a simple external DNS domain set up and in opnsense I have some simple port forward rules set up.

I then have some application on my phone that use these port forward rules. They work fine on the public network (e.g. coming in on the WAN) but when I'm on the LAN they don't seem to reverse back in to the LAN network.

Any idea what I could be doing wrong here.
 

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2