Two instances of OPNsense - Can't get access to the internet

Started by apexapollo, July 09, 2019, 04:10:52 PM

Previous topic - Next topic
Hey there,

first and foremost my setup:

I have two instances of OPNsense running on my ESXi 5.5 server.

One instance is acting as an outside firewall, meaning that the LAN interface has an IP address within my server network and the WAN interface has an IP address related to the router provided by my ISP.
This instance of OPNsense has only one rules enabled, in which is set that everything can get in and out.

The other instance is my inside firewall. At the moment, everything is passed through as well, for testing the connection to the other firewall. The LAN interface directs to the same server network, but there is no "real" WAN interface. I added the virtual switch on the ESXi server a second time to gain access to a "WAN" interface (in this case, it is OPT1). To this, I assigned another IP in the server network.

The default GW on the outside firewall obviously is the ISP router, on the inside firewall it's the outside firewall.

However, both firewalls can ping each other through LAN and internet access works perfectly fine through the WAN interface of the outside firewall.
But I just can't get a working internet connection on the inside firewall.
Do you have any idea how to get this to work?

Please note that I am a complete newbie to this topic and have never worked with firewalls before.

Thanks in advance!

Are you allowing private networks on the WAN interface of your internal firewall?

Also, what are your requirements? Dual firewall DMZ is a bit old-fashioned; one-arm DMZ is easier.

Bart...

Yes, private networks are allowed.
This is definitely not the final configuration. Eventually I will block everything on the inside firewall and create rules to only let specific things pass.
So in the end, there will only be one DMZ. Both firewalls are only open just for now, that will be fixed later.
I'm using two firewalls, because another firewall with different networks will be added by my colleague.