acl goodclients {10.5.10.0/24;10.6.10.0/24;172.16.55.0/24;172.16.60.0/24;172.16.61.0/24;172.16.62.0/24;};options {……allow-query {goodclients;};}
Are the devices able to resolve host names?
Is your outbound NAT in automatic or hybrid mode?
If so does it show automatically generated rule for the VLANs?
No, I'm not able to resolve hostnames.
Run nslookup or dig on the devices to find out, which DNS server is requested. What do you get?Ensure that the requests are not blocked by OPNsense firewall.
The nslookup and dig returns the DNS server of the inferface IP 10.5.11.1 or 10.5.12.1.
I tried changing the DNS server to my local DNS server and times out.
And does it resolve successfully?
So you have a different local DNS server running?If so you have to state its IP in the DHCP server settings.
The uplink port should have PVID 1 and be a member of all VLANs, tagged.