Quote from: OPNenthu on Today at 09:23:27 PM[...]I want to try this myself but the ping command you gave doesn't work in OPNsense.[...]
Microsoft Windows [Version 10.0.19045.4529]
(c) Microsoft Corporation. All rights reserved.
C:\Users\User>ping google.com -f -l 1472
Pinging google.com [142.251.116.102] with 1472 bytes of data:
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=14ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Reply from 142.251.116.102: bytes=1472 time=19ms TTL=104
Ping statistics for 142.251.116.102:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 14ms, Maximum = 19ms, Average = 17ms
C:\Users\User>
Quote from: Sisko on Today at 10:08:58 AM[,,,]I also recently replaced my ISP's cable modem /w a Netgear CM2000 which meets and exceeds the specs of the ISP's modem.[...]
Quote from: falken on Today at 09:28:24 PMI can't find anything official on how it should handle "blank" subnets, but the method right now is it will parse any lists that are blank in addition to any other policy it did match on. I agree if nothing else, it should be a feature request.
QuoteAs far as forcing the route though the GUA to get there, you would have needed to add a firewall rule to allow that behavior, otherwise it wouldn't route. DNS is also not a security feature. They can also just type the IP in directly, add it their local hosts file, or many other various methods
Quote from: senseOPN on Today at 09:27:56 PMBUT, in my Interfaces below the old rules, I still see "Floating rules" and those are clearly MY floating rules, not automatically created!I can't tell from your screenshot what those Floating rules are but I think they would all be yours. System-generated and automatic rules go into their own categories.
They seem to be the same as from the new rules, at least I can see one new rule that I added in the new rules section after the upgrade.
But they have no Delete button.
Quote from: senseOPN on Today at 09:27:56 PMThis seems to be a fundamental change to before, where changing such things would never change the priority (rule-number)!
And, I cannot have "late" rules anymore for more than one Interface! Now, such a rule get's moved to the front.
Quote from: OPNenthu on March 01, 2026, 10:06:08 AMUnsolicited advice: once you've migrated, don't look back at the legacy UI for any reason. Just forget it exists and try to acclimate to the new one (which is a lot like a spreadsheet). The exception is for Outbound NAT as that isn't migrated yet.