Connections suddenly blocked on LAN interface

Started by BoerBart, September 29, 2026, 06:09:25 PM

Previous topic - Next topic
I've been using OPNsense for about two years now, never had any issue, until a few days back. I've set up a few VLANs in OPNsense that are all functioning properly, but I'm having issues on the LAN interface since recently. My idea is that the issue started either because of:

- An OPNsense update;
- Using the rule migration tool.

OPNsense version: 26.7.4_1 26.7.5 - As of Wed Sep 30.
Architecture: amd64
Updated on: Sun Sep 20 15:14:10 UTC 2026 - Wed Sep 30 17:04:38 UTC 2026

I'm running two Peladn N95 nodes in Proxmox, both are fully up-to-date as well.
Firmware version of the Peladn network devices: rtl8168h-2_0.0.2 02/26/15

The two peladn nodes, my PC, phone and such are all on the same LAN interface. OPNsense is running on a VM in the Proxmox cluster, i've got quite a few other containers/VMs running, each in several VLANs. Two days ago (after running the migration tool), I noticed that the internet on my phone got spotty, and today i've noticed it on my PC. When looking at the firewall logs, I noticed that (randomly to me) connections are being dropped, though not all. A page or Whatsapp message sometimes loads/gets delivered, and the next time it keeps loading/sending. Here are the output details for one of them of the Live View:

__timestamp__    2026-09-29T15:48:11
ack    3901492930
action    [block]
anchorname   
datalen    39
dir    [in]
dst    34.54.185.247
dsthostname   
dstport    443
ecn   
id    13033
interface    vtnet0
ipflags    DF
ipversion    4
label    Default deny / state violation rule
length    91
offset    0
protoname    tcp
protonum    6
reason    match
rid    02f4bab031b57d1e30553ce08e0ec131
rulenr    13
seq    3881579953:3881579992
src    192.168.1.225
srchostname   
srcport    40708
status    2
subrulenr   
tcpflags    PA
tcpopts   
tos    0x0
ttl    64
urp    63

When looking at Firewall -> Diagnostics -> Statistics -> Rules, my assumption that this is rule 13:
@13 block drop in log inet all label "02f4bab031b57d1e30553ce08e0ec131"

    15
    :
    
    59
    :
     25 2026
    evaluations
    :
     11538
    packets
    :
     1700
    bytes
    :
     171359
    states
    :
     0
    nodes
    :
     0
    limit
    :
     0
    nat/rdr
    :
     0
    route
    :
     0
    inserted
    :
     uid 0 pid 0
    state_creations
    :
     0
    time
    :
     tue sep 29

This issue only happens on the LAN interface, all other interfaces are running just fine. I can't seem to figure out what I can do to solve this. I do not have any other rules that block traffic on the LAN interface.

Post your network setup and all the Firewall Rules for the LAN Interface.

Is the Mini PC a Single NIC model or Dual/Quad NIC ?


And in general : The more info you provide, the less guessing we all have to do! ;)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Quote from: nero355 on September 29, 2026, 07:08:11 PMPost your network setup and all the Firewall Rules for the LAN Interface.

Is the Mini PC a Single NIC model or Dual/Quad NIC ?


And in general : The more info you provide, the less guessing we all have to do! ;)

Sure - I'll do my best in providing what's needed; I don't have much experience networking-wise, so it's a bit of guessing what is needed.

Network setup
Modem of provider --> TP-Link archer AX50 (bridge mode) --> TP-Link TL-SG108E switch --> single NIC Mini PC.

Switch port layout
Port 1 is TP-Link archer AX50
Port 2 is Single NIC Mini PC #1
Port 2 is Single NIC Mini PC #2

Switch VLAN (802.1Q) configuration
VLAN ID     VLAN Name     Member Ports     Tagged Ports     Untagged Ports
1     Default     1-8    1-8   
5     Redacted    2-3    2-3       
10    Redacted    2-3    2-3       
15    Redacted    2-3    2-3       
20    Redacted    2-3    2-3       
25    Redacted    2-3    2-3       
30    Redacted    2-3    2-3       
50    Redacted    2-3    2-3       
80    Redacted    2-3    2-3       
101   Redacted    2-3    2-3       
110   Redacted    2-3    2-3       
111   Redacted    2-3    2-3       

All firewall rules that are either directly on the LAN interface, or the rule itself contains multiple interfaces, including LAN, are exported to a csv file that can be downloaded here:
https://filebin.net/aer3hx75u8wj72il

If more information is needed - happy to deliver more. I've restarted all devices/networking equipment earlier today without luck.

Today at 06:00:54 PM #3 Last Edit: Today at 06:03:10 PM by nero355
Quote from: BoerBart on September 29, 2026, 08:33:36 PMNetwork setup
Modem of provider --> TP-Link archer AX50 (bridge mode) --> TP-Link TL-SG108E switch --> single NIC Mini PC.
Why have both a Modem and the TP-Link in Bridge Mode there ?!

QuoteSwitch port layout
Port 2 is Single NIC Mini PC #1
Port 2 is Single NIC Mini PC #2
To be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?

QuoteSwitch VLAN (802.1Q) configuration
VLAN ID     VLAN Name     Member Ports     Tagged Ports     Untagged Ports
1     Default     1-8    1-8
Watch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!

QuoteAll firewall rules that are either directly on the LAN interface, or the rule itself contains multiple interfaces, including LAN, are exported to a csv file that can be downloaded here:
https://filebin.net/aer3hx75u8wj72il
It seems you only have the two Default Any to Any Rules for IPv4 and IPv6 active for the LAN Interface so I guess that's OK.

I do see some things that might benefit from double checking the rules vs. a default setup or at least testing them with improved values.
For example the rules where no Interface is mentioned.


Running everything via a Single NIC and using Proxmox to manage all the VM/LXC traffic could be the issue here, but I could be wrong...

If I am honest I would stop using OPNsense this way and replace the Archer with a nice Quad Port NIC Intel Mini PC with Intel NICs and run OPNsense directly on it without any Virtualisation in between :)
Another option is checking if you can run OpenWRT on the Archer and have something similar to OPNsense that way without buying anything new!
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Today at 07:30:50 PM #4 Last Edit: Today at 09:27:45 PM by BoerBart
Quote from: nero355 on Today at 06:00:54 PMWhy have both a Modem and the TP-Link in Bridge Mode there ?!

The TP-link is running in bridge mode to have WiFi on the first floor. There's an UTP cable running from the first floor to the second, where all the other components are, hence it's all hooked up to the TP-Link router.

Quote from: nero355 on Today at 06:00:54 PMTo be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?

I'm not a 100% sure, so i'll go and check. For my understanding, how would that cause random connections being dropped on the LAN interface?

Quote from: nero355 on Today at 06:00:54 PMWatch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!

Thanks for the info - I'll have a look at that later. It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.

I'll go over the rules again to see if there's anything off. Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?

OpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago. Of course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up. Next to that, it seems to be somewhat specific. My PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.

I've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything. I've also patched OPNsense to the latest firmware version (26.7.5), without luck.

**Added later**
In the meantime, I've swapped out the TP-Link router for a TP-Link switch, no change to the issue. I've stopped all (unnecessary) VMs and LXC containers in Proxmox, no change to the issue. I've moved the Opnsense VM to the other node, also no change to the issue.

Quote from: BoerBart on Today at 07:30:50 PMThe TP-link is running in bridge mode to have WiFi on the first floor.
But that would mean each WiFi device has a WAN IP Address ?!

I am pretty sure your ISP does not like that...

QuoteI'm not a 100% sure, so i'll go and check.

For my understanding, how would that cause random connections being dropped on the LAN interface?
I was thinking maybe you pick up the wrong DHCP Settings on your Client from time to time... Who knows... I have seen a lot of weird stuff throughout the years ;)

QuoteThanks for the info - I'll have a look at that later.
It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.
Wait...

The Modem is Bridged... right ?!

QuoteI'll go over the rules again to see if there's anything off.
Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?
From the top down indeed and as they all seem to be so called 'Quick Rules' then it's basically the first rule that gets hit is the way to go IIRC :)

QuoteOpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago.
Too bad! :(

QuoteOf course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up.
Next to that, it seems to be somewhat specific.
Sometimes there is a simple reason such as simply a configuration that was wrong in the first place and after "Change X" to the software the issue rises to the surface so to speak...

QuoteMy PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.
It could be something local to them but you will have to figure that out on your own.

One of the things I was thinking about is A-Symmetric Routing but I am not sure how that would apply here, however as stated before : I have seen weirder things before... A LOT of weird things...

QuoteI've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything.
Good idea anyway!

Quote**Added later**
In the meantime, I've swapped out the TP-Link router for a TP-Link switch, no change to the issue.

I've stopped all (unnecessary) VMs and LXC containers in Proxmox, no change to the issue.
I've moved the Opnsense VM to the other node, also no change to the issue.
Bummer... :(
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)