Firewall traffic paths

How packets can move through the OPNsense firewall: which networks hang off it, and what each kind of traffic goes through on the way. Pick a path to light it up.

Interactive map

uplink OpenVPN WireGuard Internet ISP uplink Parents VPN clients StarPort site remote network OPNsense firewall Rules + NAT 1. firewall rules 2. port forwards (DNAT) 3. routing 4. outbound NAT default: block inbound from the Internet Firewall web UI management interface WANem5 ParentsVPNovpns1 StarPortwg1 LANVLAN 10 ManagementVLAN 25 ServerNetVLAN 30 Home LAN PCs, phones, TVs Management net infrastructure Server network published servers × ×
possible link path taken blocked path

Path by path

Allowed · port forward

Internet → published server

  1. A packet arrives on WAN addressed to one of the firewall's public addresses.
  2. Bogon ranges and a geo-block list are dropped first. Anything without a matching pass rule is dropped.
  3. A destination NAT rule swaps the public address and port for the private server's, and a WAN pass rule has to allow it too.
  4. The packet is routed out of ServerNet. Replies follow the state table back. One server also sends its own traffic from a dedicated public address rather than the shared one.

Only a handful of forwards are switched on. Older ones are kept in the config but disabled.

Allowed · NAT

Home LAN → Internet

  1. A device on the Home LAN (VLAN 10) sends to the firewall as its gateway.
  2. The LAN rules allow any destination.
  3. Outbound NAT rewrites the source to the WAN address.
  4. The packet leaves on em5 toward the ISP gateway, which is currently reporting online with no packet loss.
Allowed · NAT

Server network → Internet

  1. A server in ServerNet (VLAN 30) sends outbound traffic.
  2. An “allow server network outbound” rule matches, after the block rules for internal networks and the web UI (see the blocked path below).
  3. Outbound NAT uses the shared WAN address, or the server's dedicated public address where one is mapped.
  4. The packet leaves on em5.
Allowed · routed

Home LAN ↔ StarPort

  1. The routing table sends the StarPort site's private ranges (two prefixes) out of the WireGuard interface rather than the WAN default route.
  2. LAN rules allow it, and the WireGuard tunnel carries it to the peer over the WAN link.
  3. In the other direction, the StarPort rules allow traffic in from the tunnel.
  4. One home address range is translated to a different range on the StarPort interface so the two sites don't overlap.
Allowed · broad

Parents VPN

  1. A client connects to the OpenVPN server on a WAN port that is open to anyone. The VPN login is the gate, not the firewall rule.
  2. The session lands on the ParentsVPN interface (ovpns1), which has its own subnet.
  3. The ParentsVPN and OpenVPN group rules allow any destination, so clients can reach the home LAN, management net, server network and the Internet.
  4. Firewall-originated traffic toward this interface is pinned to a dedicated gateway.
Blocked

Server network → inside

  1. A server in ServerNet tries to reach the Home LAN.
  2. A block rule drops it. The rule covers the LAN and two more internal interfaces.
  3. A second rule stops ServerNet from reaching the firewall's web UI.
  4. Only Internet-bound traffic from ServerNet is allowed through (see the path above).
Allowed · restricted

Admin access

  1. The firewall's own web UI is reachable from a short list of allow-listed sources on WAN.
  2. From the Home LAN, anti-lockout rules always keep the UI and SSH reachable.
  3. Repeated failures trigger the lockout table, which blocks the source.
  4. ServerNet is blocked from the UI entirely.

Interfaces

NameDeviceWhat it is
WANem5ISP uplink. A block of public addresses sits on this port; the default route goes out through it.
LANvlan03Home network, VLAN 10 on the em0 trunk.
ManagementNetvlan02Infrastructure management network, VLAN 25 on the em0 trunk.
ServerNetvlan0.30Servers published to the Internet, VLAN 30 on the em0 trunk.
StarPortwg1WireGuard site-to-site tunnel to the StarPort network.
ParentsVPNovpns1OpenVPN server for remote access.
Unusedem1–em4Physical ports with no cable connected.

Snapshot of the firewall configuration read through its read-only API on 2026-10-01. This site is public, so addresses, port numbers and allow-listed sources are left out on purpose. The map is a simplified picture; the real rule set has more exceptions than fit here.