Quote from: mfreudenberg on December 08, 2025, 07:04:58 PMIch habe das Gefühl, dass der Switch korrekt konfiguriert ist. Immerhin kommt ein Ping zum OPNSense durch.dann versuch es mal etwas weiter.
Quote from: pfry on December 08, 2025, 06:41:02 PMQuote from: coffeecup25 on December 08, 2025, 03:30:55 PM[...]My first instinct was to use 'problem decomposition'.[...]
Perhaps "System: Configuration: Backups" -> "Downloads", download and search for ".5." or similar. But it doesn't sound like it'll be there, as hitting the default deny suggests an external source.Quote from: Untoasted9563 on December 08, 2025, 12:05:51 PM[...]ping -S 192.168.10.1 8.8.8.8 is successful[...]
Is it? Typo, or another subnet?
vlan0.01 [MGMT] vtnet1 (mac-adresse) [LAN] 1 Best Effort (0, default)
vlan0.50 [Clients] vtnet1 (mac-adresse) [LAN] 50 Best Effort (0, default) Internet
vlan01.20 [Heimautomation] vtnet1 (mac-adresse) [LAN] 20 Best Effort (0, default) Heimautomation
## Basic Configuration
Enable [x] Enable Interface
Lock [x] Prevent interface removal
Identifier opt3
Device vlan0.50
Description Clients
## Generic configuration
Block private networks [ ]
Block bogon networks [ ]
IPv4 Configuration Type Static IPv4
IPv6 Configuration Type None
MAC address [...]
Promiscuous mode [ ]
MTU [...]
MSS [...]
Dynamic gateway policy [ ] This interface does not require an intermediate system to act as a gateway
## Static IPv4 configuration
IPv4 address 172.17.50.253
IPv4 gateway rules Disabled
IPv4 TCP Clients net * Clients address 443 (HTTPS) * * Allow OPNSense HTTPS-Webfrontend from Clients-Net (debugging)
IPv4 * Clients net * * * * * -
IPv4 TCP Clients net * WAN net 443 (HTTPS) * * -
IPv4 TCP/UDP Clients net * WAN net 53 (DNS) * * -
IPv4 TCP/UDP Clients net * Clients address 53 (DNS) * * Allow access to DNS-Servers on the Internet
IPv4 * Clients net * ! PrivateNetworks * * * Default allow LAN to any rule
| Port | VLAN-Member | Tagging |
| ---- | ----------- | ---------- |
| 1 | 50 | Tx Tagging |
| 2 | - | - |
| 3 | 50 | - |
| 4 | 50 | - |
| 5 | 50 | Tx Tagging |
VLAN50
---
Ports: 2 4 6
Ports: 1 3 5
T/U: - U T
T/U: T U T
Quote from: coffeecup25 on December 08, 2025, 03:30:55 PM[...]My first instinct was to use 'problem decomposition'.[...]
Quote from: Untoasted9563 on December 08, 2025, 12:05:51 PM[...]ping -S 192.168.10.1 8.8.8.8 is successful[...]
Quote from: knebb on December 08, 2025, 04:56:22 PMI got it so far the pipes limit the bandwidth (upper limit) while the queues weight the traffic according to the rules. Queues can get oignoredd when a rule sends the traffic to a pipe immediately ( I do not know how any weight is then calculated). Got this so far.
Quote from: knebb on December 08, 2025, 04:56:22 PMBut how are the (firewall-)rules coming into the game you mentioned above? Do I overwrite everything and directly assign traffic to pipes/queues? How are they different (except scheduling possibility) from the shaper rules?