OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • All outbound traffic seems to be "let out anything from firewall host itself"
« previous next »
  • Print
Pages: [1]

Author Topic: All outbound traffic seems to be "let out anything from firewall host itself"  (Read 3822 times)

jonm

  • Jr. Member
  • **
  • Posts: 51
  • Karma: 2
    • View Profile
All outbound traffic seems to be "let out anything from firewall host itself"
« on: April 07, 2021, 12:01:27 pm »
I was looking at the live view of my firewall logs and I notice that all my outbound traffic appears to be Interface:wan, source: my WAN IP address, and label "let out anything from firewall host itself (force gw)".

Is this to be expected or have I somehow messed something up? Everything is working OK, as far as I can tell, but I would have thought that I should see the all the various source devices' IP addresses/hostnames in the log rather than the wan interface, shouldn't I?
Logged

Greelan

  • Hero Member
  • *****
  • Posts: 1028
  • Karma: 72
    • View Profile
Re: All outbound traffic seems to be "let out anything from firewall host itself"
« Reply #1 on: April 07, 2021, 12:45:13 pm »
Quote from: jonm on April 07, 2021, 12:01:27 pm
I was looking at the live view of my firewall logs and I notice that all my outbound traffic appears to be Interface:wan, source: my WAN IP address, and label "let out anything from firewall host itself (force gw)".

Is this to be expected or have I somehow messed something up? Everything is working OK, as far as I can tell, but I would have thought that I should see the all the various source devices' IP addresses/hostnames in the log rather than the wan interface, shouldn't I?
Perfectly normal. Traffic destined for the internet from local hosts comes into OPNsense on the LAN/VLAN interface, gets NATed, and then exits OPNsense on the WAN interface with the WAN IP (the automatic floating rule allows the egress)
Logged

jonm

  • Jr. Member
  • **
  • Posts: 51
  • Karma: 2
    • View Profile
Re: All outbound traffic seems to be "let out anything from firewall host itself"
« Reply #2 on: April 08, 2021, 11:34:36 am »
OK, that makes sense, thanks.
Logged

jonm

  • Jr. Member
  • **
  • Posts: 51
  • Karma: 2
    • View Profile
Re: All outbound traffic seems to be "let out anything from firewall host itself"
« Reply #3 on: May 11, 2021, 02:42:38 pm »
Apologies for replying to an oldish thread but this is still bothering me.

I've been looking at ntopng which is working but exhibits a similar problem - all the active flows show the client as the router itself. This is way less useful than I had hoped, I'd like to see what the individual clients are. Is this normal? Is it related to the way the firewall traffic is showing in the logs as in my root post? Is there any way to show the individual clients?

Thanks

Jon.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • All outbound traffic seems to be "let out anything from firewall host itself"
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2