Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
OPN on Hetzner vSwitch w/public subnet, natted VMs can't browse internet
« previous
next »
Print
Pages: [
1
]
Author
Topic: OPN on Hetzner vSwitch w/public subnet, natted VMs can't browse internet (Read 2042 times)
feedt
Newbie
Posts: 7
Karma: 1
OPN on Hetzner vSwitch w/public subnet, natted VMs can't browse internet
«
on:
July 26, 2022, 12:42:32 pm »
Good morning forum, i'm trying to integrate OPN (latest stable) as a firewall on my XCPNG (xen) cluster on Hetzner but cannot get VM behind it browsing web.
Some tech stuff: on Hetzner, each physycal host is connected in a vswitch (vlan) with a public subnet binded to it (
https://docs.hetzner.com/robot/dedicated-server/network/vswitch/
). So, in a guest vm, if we attach his interface to the vswitch/vlan (MTU 1400) and give an ip from the public subnet, the VM can browse with this new public ip (tested, working).
The problem: i made the same exact configuration for the WAN side of OPNsense istance with some VM connected to the LAN (behind NAT) and those VM can only ping/resolve external addresses but got timeout when browsing internet. Tried reset, pfctl -d, review ruleset but nothing seems help
Any hint? Thank you
Logged
feedt
Newbie
Posts: 7
Karma: 1
Re: OPN on Hetzner vSwitch w/public subnet, natted VMs can't browse internet
«
Reply #1 on:
July 26, 2022, 05:21:09 pm »
Resolved, the problem was the MTU of 1400 for the vSwitch that's need to be set at VM level, leaving the default (1500) on the virtual nic at hypervisor level
«
Last Edit: July 26, 2022, 09:13:48 pm by feedt
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.1 Legacy Series
»
OPN on Hetzner vSwitch w/public subnet, natted VMs can't browse internet