Quote from: ricksense on January 28, 2026, 02:44:36 PMFor the time being, I can reach OPNsense dashboard even without the ruleThis might be allowed by the automatically generated "anti-lockout rule", which is not shown up by default.
Quote from: ricksense on January 28, 2026, 02:44:36 PMI also set up NAT rules for DNS redirectionNormally this also adds a rule for allowing the access.
Quote from: viragomann on January 28, 2026, 02:18:13 PMThe guide suggests to do policy-routing for all LAN traffic in step 4. This means any traffic would be sent out to the current upstream gateway (gateway group). Hence you would not be able to reach any internal destination, even not OPNsense itself.
The suggested rule in step 5 would allow DNS only to OPNsense befor this.
If DNS resolution on your internal devices works anyway without it, you either didn't state the gateway in step 4 or your internal devices are not configured to use OPNsense for DNS resolution.