my work HAD planned to donate a Bunch of $$ to you to further development but if we cant even get this what seems like should be simple problem solved theres no point and would end up wasting the money migrating the config back to pfsense.
Hi Franco,never could get it to work. opnsense wouldnt pass the traffic.i did what you suggested ,wouldnt pass traffic. rebooted , still wouldnt pass traffic.disabled the firewall, wouldnt pass traffic afterwards, rebooted, still wouldnt pass traffic.i could ssh into the opnsense box and get a shell and ping and traceroute all over the internet but wouldnt pass traffic from *ANY* of my vlans.i could ssh into the opnsense box from my Juniper SRX on the edge of our networks on the wan side.there were no rules under nat even after i disabled it.i even added a static route with the SRX as the gateway, no difference.
Let's check some settings:* Your WAN interface should be set up and have an IP and a gateway* Your VLAN interfaces should be set up and have an IP, but no gateways* You should have a default gateway set up under "System: Gateways: Single" that can reach the internet (the WAN interface gateway)* Under "Firewall: Settings: Advanced" "Network Address Translation" all options should be unchecked, "Disable all packet filtering. " should be unchecked* Under "Firewall: NAT: Outbound" Manual outbound NAT rule generation should be selected and you should remove any rules* Under "Firewall: Rules: (your VLAN interfaces)" you should add an allow rule matching everything** Under "Firewall: Rules: your WAN interface" you should add allow rules matching inbound traffic as required(You possibly don't want to allow all traffic from your VLAN interfaces but I'm trying to keep things simple for now)You could check "Disable all packet filtering" and then not have any firewall rules - if you really want a plain router with no filtering at all.If you're still having trouble and don't see any settings matching that, can you try some tracerts?This may be a stupid question, but have you made sure you don't have some sort of port security feature on your switch preventing your opnsense router from being able to work properly sending with various different source addresses? if that was the case that would prevent pfsense working too, but maybe you have setup a new test environment for opnsense so it seemed worth checking.