Rule migration breaks NAT/Port forwarding

Started by trumee, February 07, 2026, 04:51:52 PM

Previous topic - Next topic
Hello,

I have a dual WAN setup and i am trying to upgrade the router over the internet. I did a migration but my forwarded ports from WAN stopped working. I rolled back to the snapshot with the old rules.

I have a few questions,

  • Can i keep using using old rules and continue making changes to opnsense without breaking it (e.g. suricata)? Or does the function now depend on New rules?
  • I followed the migration assistant. However i pressed the `Apply Button` in Step 4 and Step 5. Was that ok?
  • Do i need to reboot the router after migration? I did not reboot, and could that be the reason that NAT broke for me.

If I have to guess, your NAT worked but you had no allow rules for those? A reboot is not required.

Quote from: trumee on February 07, 2026, 04:51:52 PMCan i keep using using old rules and continue making changes to opnsense without breaking it (e.g. suricata)? Or does the function now depend on New rules?
@franco has mentioned multiple times that there is no immediate need to migrate the Firewall Rules since the whole thing is "Work in Progress" for now and the moment that you will be more or less forced to do so is far, far, far away from now ;)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

February 08, 2026, 06:16:06 AM #3 Last Edit: February 08, 2026, 06:27:26 AM by jysl
Same thing happen to me, it have to do with the reply to on multi wan that is not on the default gateway. I am not sure what the intend behavior is. But the below topic fixed for me

https://forum.opnsense.org/index.php?topic=50760.

Interesting, at least rules.debug shows no reply-to at all. Not sure if it was present there with an older config.

February 08, 2026, 10:29:36 AM #5 Last Edit: February 08, 2026, 11:01:20 AM by Bob.Dig
.

February 08, 2026, 10:54:14 AM #6 Last Edit: February 08, 2026, 10:56:22 AM by jysl
Here the setting that work only

https://imgur.com/9KoAz6a

I try setting the "Gateway" to the same gateway as the "reply to" and "reply to" none, but that didn't work
Also try the "Gatway" none, Checked the "Disable reply to" and "reply to" none, that also not work

February 08, 2026, 10:56:37 AM #7 Last Edit: February 08, 2026, 11:02:35 AM by Bob.Dig
Yep, you only can set it in advanced mode of that rule, that makes sense. Why it is not the default anymore makes less sense to me.