Where should I put the maintence interface?

Started by timlab55, Today at 03:32:12 PM

Previous topic - Next topic
I'm sure a lot of people who are new to OpnSense would like to know this as well.  For example, and again I say "for example", my home network is on 192.168.75.0/24, and my OpnSense is on 192.168.2.0/24.  So where would the maintenance interface go (which ip address)?

If your home LAN is 192.168.75.0/24 then the LAN interface of OPNsense must also have an IP address in that network. Picking an address from 192.168.2.0/24 for OPNsense won't work.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

And after that, how many ports do you have on your firewall hardware?

In theory you would need the following:

LAN
WAN
Management

ports if you want to do things the easy way. You can manage the firewall from the LAN (the default configuration). Many of us just make a maintenance network if we have an extra port and use it kind of as backup if the LAN port gives us a problem. And I've had to use mine when I did something that knocked out all my other ports, makes a good use of those onboard Realtek ports that a lot of us have, works good enough to get in and fix your mistake.

This is along the same problem.  I've been following the video from "Home Network Guy - How To Set Up A transparent Filtering Bridge on OPNsense" because I'm very slowly learning about networking.  I mean, to me it's step by step (which is what I need).  Two problems.  #1:  One day, I can get it to work (the section I'm learning about), and the next day, I go back and make a correction or something, and it doesn't work.  Come back a week later and it does work.  Doesn't make sense to me.  And yes, he does talk about making the maintenance interface.  He the reason for my question is because of what he is saying, I have no clue about.  In his video he states "You will need to ensure the static IP address is not located in the DHCP range you have set on your primary router and does not conflict with any other static IP addresses on your management network."  So again, with the opening question and this, what should my ip address be for the MGMT interface?

Why are you trying to set up a transparent filtering bridge? The most complex error prone hard to debug configuratiom of a firewall existing? Set up OPNsense as a router and firewall which is the well documented default.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)