OPNsense 26.7 blocks LAN traffic

Started by ricksense, September 30, 2026, 05:27:00 PM

Previous topic - Next topic
September 30, 2026, 05:27:00 PM Last Edit: September 30, 2026, 05:44:57 PM by ricksense
Hi everyone,

I upgraded to OPNsense 26.7, but the default LAN pass rule no longer seems to work—I can't even access the web GUI from the LAN subnet. I have to disable the firewall (pfctl -d) via the console just to reach it. Since this is just a lab setup, I reset the firewall entirely and recreated the rule from scratch, but the issue persists. I'm not sure what I'm missing—could you help me troubleshoot this?
Thanks






What happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: nero355 on September 30, 2026, 06:24:33 PMWhat happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?

Or are they already Enabled ?!

Yes, already enabled. Anyway, I fixed the problem(s) eventually, but I had to struggle a lot.
Very strange behavior compared to the old version.
Thanks

What exactly was your fix, please?
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Quote from: Patrick M. Hausen on September 30, 2026, 09:42:02 PMWhat exactly was your fix, please?

Of course!

Here is an explanation of what I did to configure the firewall rules successfully. Frankly, it barely makes sense even to me, since I simply reapplied the exact configuration I had in the previous version. After setting and applying the LAN pass rule again, I used the following commands in the shell: pfctl -F state and pfctl -e

After that, even though my PC could access the OPNsense dashboard, it still couldn't reach the internet. I enabled gateway monitoring (monitoring IP: 8.8.8.8), and checking 'Use System Nameservers' in the Unbound settings (enabling DoT got the job done as well).