Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
LAN firewall rule questions
« previous
next »
Print
Pages: [
1
]
Author
Topic: LAN firewall rule questions (Read 1472 times)
paradox55
Newbie
Posts: 16
Karma: 0
LAN firewall rule questions
«
on:
October 26, 2020, 01:11:16 am »
I've started to tinker around with rules and noticed every 20-24 hours I have to allow all traffic into my network again in order for my wireguard services (which have been running for months with no issue) to function again.
Currently I am blocking all services (LAN) other then ports 53, 853, 80 and 443 with the ssh port and wireguard ports open. ICMP is also open.
Wireguard external IP(s) are whitelisted and can bypass all of the lan rules.
This problem also goes away instantly when all traffic is allowed on the interface...
It's a constant 20-24 hour cycle.
The services over wireguard don't stop working. They just start taking minutes to resolve and load. At first I thought it was a peering issue between myself and the server but then noticed that allowing all traffic fixes the problem..
My assumption is because I have such a tight restriction on LAN traffic there may be a cache issue or communication issue between all of the servers on my LAN. Perhaps an ARP cache issue?
I'm running the latest opnsense version, upgraded today.
Which ports/protocols do I need to open on LAN for servers to communicate with each other internally?
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
LAN firewall rule questions