At first I would like to say Hello to the OpnSense community since I am totally new here and new to the OpnSense.
Short info:
I finally managed to set up OpnSense firewall on my MiniPC, previously I have been using stock router from my ISP provider.
I am really excited of all the possibilities that OpnSense firewall can offer.
As most people setting up this kind of firewall I was concerned about my privacy.
Unforunetly as for now I do not have Switch so the router that I got from my ISP is set up now as AP for my WIFI devices which is plugged in directly to the OpnSense Firewall.
So as for now I am unable to set up vLAN that would help greatly. I am planning to purchase one in the near future along proper AP that allows vLAN.
OK so down to the problem I have setting up:
I tried to restrict WEB GUI access just to the LAN interface (192.168.1.1/24) specifically to my desktop PC (192.168.1.77) on custom port.(Same Interface)
I achieved part of that successfully:
1. Devices that are connected to the AP are not able to access WEB GUI or ping other devices. This is obviously different interface/subnet: 192.168.3.1/24
- I achieved that through System>Settings>Administration>Listen Interfaces: LAN.
2. I want to access the LAN interface just from my Desktop PC (static IP) on custom port for the WEB GUI.
-In Firewall>Rules>LAN: Please check the Screenshots for the created rule.
-In Firewall>Aliases: I created Alias for the port of the WEB Gui
(I am not sure if I overdo it but I want to manage it better later on if I need to block the access from other LAN/vLAN interfaces in the future)
Then I have proceeded to the Settings>Admninistration> and changed the TCP port to 6667, upon saving I was unable to reach WEB GUI at all.
I then had to backup the system to previous state through the OpnSense.
I would like to ask the Community for any guidance, insight on what I am missing or doing wrong(or both haha)
I have also attached screenshot with Nat Portforward rules, basically just one 'automatic' rule.
I appreciate your help, thank you!
#edit:
Previously uploaded wrong image which was meant to show firewall rule
Short info:
I finally managed to set up OpnSense firewall on my MiniPC, previously I have been using stock router from my ISP provider.
I am really excited of all the possibilities that OpnSense firewall can offer.
As most people setting up this kind of firewall I was concerned about my privacy.
Unforunetly as for now I do not have Switch so the router that I got from my ISP is set up now as AP for my WIFI devices which is plugged in directly to the OpnSense Firewall.
So as for now I am unable to set up vLAN that would help greatly. I am planning to purchase one in the near future along proper AP that allows vLAN.
OK so down to the problem I have setting up:
I tried to restrict WEB GUI access just to the LAN interface (192.168.1.1/24) specifically to my desktop PC (192.168.1.77) on custom port.(Same Interface)
I achieved part of that successfully:
1. Devices that are connected to the AP are not able to access WEB GUI or ping other devices. This is obviously different interface/subnet: 192.168.3.1/24
- I achieved that through System>Settings>Administration>Listen Interfaces: LAN.
2. I want to access the LAN interface just from my Desktop PC (static IP) on custom port for the WEB GUI.
-In Firewall>Rules>LAN: Please check the Screenshots for the created rule.
-In Firewall>Aliases: I created Alias for the port of the WEB Gui
(I am not sure if I overdo it but I want to manage it better later on if I need to block the access from other LAN/vLAN interfaces in the future)
Then I have proceeded to the Settings>Admninistration> and changed the TCP port to 6667, upon saving I was unable to reach WEB GUI at all.
I then had to backup the system to previous state through the OpnSense.
I would like to ask the Community for any guidance, insight on what I am missing or doing wrong(or both haha)
I have also attached screenshot with Nat Portforward rules, basically just one 'automatic' rule.
I appreciate your help, thank you!
#edit:
Previously uploaded wrong image which was meant to show firewall rule
"