Okay, now I have my first problem. I can’t ping from VyOS to anything even though i’ve set default action accept on LOCAL_to_X.
When I ping 8.8.8.8 it says network unreachable - if I ping interface ‘eth0’ it does not receive a reply.
Rulesets Information
ipv4 Firewall “forward filter”
Rule Action Protocol Packets Bytes Conditions
1 accept all 0 0 ct state { established, related } accept
2 drop all 0 0 ct state invalid
default drop all 0 0
ipv4 Firewall “input filter”
Rule Action Protocol Packets Bytes Conditions
1 accept all 63 4504 ct state { established, related } accept
2 drop all 0 0 ct state invalid
100 accept all 0 0 icmp type echo-request accept
200 accept tcp_udp 0 0 meta l4proto { tcp, udp } th dport 53 accept
800 accept tcp 0 0 tcp dport 22 ip saddr 192.168.11.0/24 prefix “[ipv4-INP-filter-800-A]” accept
default drop all 21 9832
ipv4 Firewall “name IOT_to_LAN”
Rule Action Protocol Packets Bytes Conditions
10 accept all 0 0 ct state { established, related } accept
11 drop all 0 0 ct state invalid
default drop all 0 0
ipv4 Firewall “name IOT_to_LOCAL”
Rule Action Protocol Packets Bytes Conditions
200 accept tcp_udp 0 0 meta l4proto { tcp, udp } th dport 53 accept
default drop all 0 0
ipv4 Firewall “name IOT_to_WAN”
Rule Action Protocol Packets Bytes Conditions
300 accept tcp_udp 0 0 meta l4proto { tcp, udp } th dport 443 accept
default drop all 0 0
ipv4 Firewall “name LAN_to_IOT”
Rule Action Protocol Packets Bytes
default accept all 0 0
ipv4 Firewall “name LAN_to_LOCAL”
Rule Action Protocol Packets Bytes Conditions
100 accept all 0 0 icmp type echo-request accept
200 accept tcp_udp 0 0 meta l4proto { tcp, udp } th dport 53 accept
800 accept tcp 63 4504 tcp dport 22 prefix “[ipv4-NAM-LAN_to_LOCAL-800-A]” accept
default drop all 0 0
ipv4 Firewall “name LAN_to_WAN”
Rule Action Protocol Packets Bytes Conditions
1000 accept all 0 0 accept
default accept all 0 0
ipv4 Firewall “name LOCAL_to_IOT”
Rule Action Protocol Packets Bytes
default accept all 0 0
ipv4 Firewall “name LOCAL_to_LAN”
Rule Action Protocol Packets Bytes
default accept all 36 6528
ipv4 Firewall “name LOCAL_to_WAN”
Rule Action Protocol Packets Bytes
default accept all 0 0
ipv4 Firewall “name WAN_to_IOT”
Rule Action Protocol Packets Bytes Conditions
10 accept all 0 0 ct state { established, related } accept
11 drop all 0 0 ct state invalid
default drop all 0 0
ipv4 Firewall “name WAN_to_LAN”
Rule Action Protocol Packets Bytes Conditions
10 accept all 0 0 ct state { established, related } accept
11 drop all 0 0 ct state invalid
default drop all 0 0
ipv4 Firewall “name WAN_to_LOCAL”
Rule Action Protocol Packets Bytes Conditions
10 accept all 0 0 ct state { established, related } accept
11 drop all 0 0 ct state invalid
default drop all 0 0
ipv4 Firewall “output filter”
Rule Action Protocol Packets Bytes
default accept all 36 6528