try to find out why 1 out of 5 machines do not work as expected.
Why floating, why out
I already enabled logging for every rule I could find. When I try to ping the "not-working" VM and look into my live view, i can see the ping in the direction "in" to the firewall, but no matching ping "out". When I try to ping one of the "working" VMs, I can see my connection "in" as well as my connection "out".
You mean by this that you don't see any out rule for that non working VM? Or its hitting a deny?
Thank you for the suggestion. But unfortunately that is what I already did: I deleted all the floating rules; and there was a rule which allowed me to ping the VMs (yes, also the trouble VM) enabled all the time. The problem is that the ping gets into the firewall (I can see that in live view), but it does not get out. It isnt denied or anything, the "out" part of the ICMP request (is it called a request?) just does not appear in the live view. I know that this could mean that logging for the rule blocking the "out" part just is not enabled, but I checked everywhere and there is no rule that rejects anything. EDIT: in the meantime, I also deleted the VM and set it up again. It now runs with a live image. I also deleted the interface (on the opnsense as well as on the hypervisor), tried with different VLAN tags and with a different set of IP addresses to be used on the interface. None of this helped in any way, the result was always the same..
I added screenshots of the rules on the interface I am currently on and the group interface of the VMs. The interface of the trouble VM has no rules set at all. From my machine, I can ping the firewall, google, other VMs, everything except the vm causing problems. From the VM, I cant ping anything except the firewall. From the other VMs, I can ping everything just as well as from the machine I am using right now.When trying to trace route, it fails at the IP address of the firewall on the interface my machine is on. I think this matches with my former observations in the live view?
I'm confused, if the interface the VM is on has no rules it shouldn't be able to ping anything.
Thinking there is a configuration issue with your vlan not putting the VM on the correct network. Would explain why your rules seem ineffective.