How packets can move through the OPNsense firewall: which networks hang off it, and what each kind of traffic goes through on the way. Pick a path to light it up.
Interactive map
possible linkpath takenblocked path
Path by path
Allowed · port forward
Internet → published server
A packet arrives on WAN addressed to one of the firewall's public addresses.
Bogon ranges and a geo-block list are dropped first. Anything without a matching pass rule is dropped.
A destination NAT rule swaps the public address and port for the private server's, and a WAN pass rule has to allow it too.
The packet is routed out of ServerNet. Replies follow the state table back. One server also sends its own traffic from a dedicated public address rather than the shared one.
Only a handful of forwards are switched on. Older ones are kept in the config but disabled.
Allowed · NAT
Home LAN → Internet
A device on the Home LAN (VLAN 10) sends to the firewall as its gateway.
The LAN rules allow any destination.
Outbound NAT rewrites the source to the WAN address.
The packet leaves on em5 toward the ISP gateway, which is currently reporting online with no packet loss.
Allowed · NAT
Server network → Internet
A server in ServerNet (VLAN 30) sends outbound traffic.
An “allow server network outbound” rule matches, after the block rules for internal networks and the web UI (see the blocked path below).
Outbound NAT uses the shared WAN address, or the server's dedicated public address where one is mapped.
The packet leaves on em5.
Allowed · routed
Home LAN ↔ StarPort
The routing table sends the StarPort site's private ranges (two prefixes) out of the WireGuard interface rather than the WAN default route.
LAN rules allow it, and the WireGuard tunnel carries it to the peer over the WAN link.
In the other direction, the StarPort rules allow traffic in from the tunnel.
One home address range is translated to a different range on the StarPort interface so the two sites don't overlap.
Allowed · broad
Parents VPN
A client connects to the OpenVPN server on a WAN port that is open to anyone. The VPN login is the gate, not the firewall rule.
The session lands on the ParentsVPN interface (ovpns1), which has its own subnet.
The ParentsVPN and OpenVPN group rules allow any destination, so clients can reach the home LAN, management net, server network and the Internet.
Firewall-originated traffic toward this interface is pinned to a dedicated gateway.
Blocked
Server network → inside
A server in ServerNet tries to reach the Home LAN.
A block rule drops it. The rule covers the LAN and two more internal interfaces.
A second rule stops ServerNet from reaching the firewall's web UI.
Only Internet-bound traffic from ServerNet is allowed through (see the path above).
Allowed · restricted
Admin access
The firewall's own web UI is reachable from a short list of allow-listed sources on WAN.
From the Home LAN, anti-lockout rules always keep the UI and SSH reachable.
Repeated failures trigger the lockout table, which blocks the source.
ServerNet is blocked from the UI entirely.
Interfaces
Name
Device
What it is
WAN
em5
ISP uplink. A block of public addresses sits on this port; the default route goes out through it.
LAN
vlan03
Home network, VLAN 10 on the em0 trunk.
ManagementNet
vlan02
Infrastructure management network, VLAN 25 on the em0 trunk.
ServerNet
vlan0.30
Servers published to the Internet, VLAN 30 on the em0 trunk.
StarPort
wg1
WireGuard site-to-site tunnel to the StarPort network.
ParentsVPN
ovpns1
OpenVPN server for remote access.
Unused
em1–em4
Physical ports with no cable connected.
Snapshot of the firewall configuration read through its read-only API on 2026-10-01. This site is public, so addresses, port numbers and allow-listed sources are left out on purpose. The map is a simplified picture; the real rule set has more exceptions than fit here.