26.1.7_3 - Firewall Logs all show SRC as GW IP

Started by zartoz, May 08, 2026, 10:23:34 PM

Previous topic - Next topic
Caveat up front, new to OPNsense.  Coming over from Untangle.

I have everything functional and started testing out cutting over but I am struggling with getting Firewall Logs to show the Source IP as my 10. internal network.  Everything is being shown as Pass with the rule "let out anything from firewall host itself (force gw)"

I do have dual WAN setup with a Group.

All the entries show the Gateway Interface IP as the Source IP.  I have tried changing the Outbound NAT from Auto to Hybrid and Manual and back again with no change.  I know I am missing something simple.  I did install Zenarmor and that can report out the LAN IP traffic so at least I have some visibility there.

Happy to output anything or try anything that would help troubleshoot as I haven't fully cutover yet and still testing.