2020-06-09

IT/TECH: OPNsense deny default rule problems

Forword
Moving from psSense to OPNsense does create a learning curve and a number of unexpected problems - at least this is my experience.

Therefore I'll post now from time to time the one or other 'highlight' that I found and potential solutions to them, at least the ones I found.

Situation
I recently installed OPNsense from scratch on a new machine, a number of interfaces, two WAN interfaces, some LAN and WiFi interfaces.

After doing the basic installation - which is quite fast and easy - I found that no traffic went through the added interfaces, except for the initial LAN.

More, and surely not helpful, I just found [..] deny default route [..] in the Firewall: Log Files: Live View. E.g. DNS queries that haven't yet been blocked are denied. Even on each interface I installed IPv4 and IPv6 allow everything rules and expected that they just work.

After researching a while forth and back, I found that none of the articles in both, OPNsense forum and elsewhere in the net, didn't help. E.g. Firewall: Diagnostics: States Reset and clicking Reset didn't help.

Potential solution / My solution
So after trying around and thinking everything through and since this is now the 5th or 6th time I (re-)install OPNsense I tried the following:
  1. Firewall: Diagnostics: States Reset - do the full reset thing
  2. Opening an SSH connection to the Firewall
  3. Choosing "11) Reload all services"
And guess what, that did the thing.

Epilogue
With pfSense I never had issues like this, but others... With OPNsense I found now a number of situations, e.g. this one in which I found this process helps.

Yet, I haven't found out why this is (the often) needed process to get OPNsense do what it should, however, I hope that this helps other newbies to OPNsense if they come across such a problem.