First of all, 1. are you connecting opnsense to edgerouter or directly?2. have you tried using the same mac address on the opnsense from edgerouter? (useful if landlord gives ip with dhcp)3. for the "Block private networks" and "Block bogon networks" part, you need to treat it the same as if you had an ISP providing you internet through dhcp within a subnet with other probably compromised hosts, you usually disable these two options if you have internal opnsenses routing between your subnets
Since all the tenets in your building are on the same subnet your situation is like logging into a hotel WiFi where all of your traffic is visible to anyone else staying in the hotel. No need to panic but just be more vigilant when you see anything odd in the logs or IDS services.At the very least, disable OPNSense GUI from WAN, disable root login into OPNSense and disable HTTP redirect for GUI (under System ==> Settings). As for the problem you posted, did you create any firewall rules for LAN? The default is "block all" and that is what seems to be happening in your case.
Enable logging for the default "allow all" rule and see the firewall logs in real time as you ping from a client machine on LAN.
Quote from: KILLERMANTV on August 16, 2022, 08:15:58 pmFirst of all, 1. are you connecting opnsense to edgerouter or directly?2. have you tried using the same mac address on the opnsense from edgerouter? (useful if landlord gives ip with dhcp)3. for the "Block private networks" and "Block bogon networks" part, you need to treat it the same as if you had an ISP providing you internet through dhcp within a subnet with other probably compromised hosts, you usually disable these two options if you have internal opnsenses routing between your subnets1. Right now I have the Sense connected to the Edgerouter, but in the future, the Sense should replace the Edgerouter.2. The IP I get from my landlord is static, so it's always the same. I didn't try with the same mac address.3. Since I have the Sense behind my Edgerouter, I think I need these two options, if I understand it correct.