Quote from: pfry on June 27, 2026, 10:31:22 PMI'd watch the live log (rule logging must be enabled) and make sure the ruleset is working as expected. (I'm lazy, and also look at the "Firewall States" dashboard widget for a total, as well as the "Sessions" and "States" GUI diags.) With so many rules I would not expect a functional loop. Also, "netstat" - "-m", "-i", perhaps "-Q", "-T", "-x", "-s" options (most have to be issued separately), and see if anything looks bad.
Quote from: WiteWulf on Today at 06:02:15 PMMy clients are now only receiving the IPv4 addresses for my PiHole and OPNsense Unbound, in that order, and will fallback to the OPNsense server if the PiHole goes away for whatever reason.
Quote from: keeka on Today at 06:43:23 PMWhy do you prefer the null routes solution?
Quote from: meyergru on Today at 06:31:15 PMI get that, but the question is : Why not ?!Quote from: nero355 on Today at 06:23:48 PMThat they would block this kind of traffic but apparently do not ?!?!Not going out the interface, only in...
Quote from: nero355 on Today at 06:23:48 PMThat they would block this kind of traffic but apparently do not ?!?!