core icon indicating copy to clipboard operation
core copied to clipboard

Port Forward reply to not getting set correctly

Open EkiciLP opened this issue 9 months ago • 3 comments

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

  • [x] I have read the contributing guide lines at https://github.com/opnsense/core/blob/master/CONTRIBUTING.md
  • [x] I am convinced that my issue is new after having checked both open and closed issues at https://github.com/opnsense/core/issues?q=is%3Aissue

Describe the bug

In a Multi-Lan setup with a VPN und a WAN: When Port-Forwarding (IPv4) from the VPN to any internal device the replies from that device always get routed through the default WAN (The Policy routing that should route all the traffic from that machine through VPN is ignored).

To Reproduce

Steps to reproduce the behavior:

  1. Have a Wireguard VPN and normal WAN
  2. Create a Port-Forward from the VPN to any machine in the local network.
  3. See (using tcpdump) that replies to these requests get routed through the normal WAN

Expected behavior

The Replies should go back to their sender.

Describe alternatives you considered

When removing the auto-generated the traffic rule from the port forward and defining one myself setting reply-to to the VPN Gateway works. So maybe the reply-to in the auto generated rule is not set correctly?

Environment

Software version used and hardware type if relevant, e.g.:

OPNsense 24.7.a_388 (amd64). Intel® Core™ i3-4160 3.6Ghz Dual Core Network Intel® I350-T2

EkiciLP avatar May 09 '24 10:05 EkiciLP