pfSense and OPNsense troubleshooting: logs, states, port forwards, captures and asymmetric routing
The vendors' troubleshooting guidance applied step by step: what the firewall log and state table prove, why a new block rule seems to do nothing, rules on the wrong interface or with the wrong ports, traffic the firewall can never see, the full port forward checklist (logs, states, WAN then LAN captures, gateway on the target, ISP blocks, NAT reflection versus split DNS, reply-to on extra WANs), and reading packet captures, asymmetric routing and harmless-looking blocked log entries. Covers both pfSense and OPNsense where their documentation differs.
- Level
- Advanced
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- pfSense / OPNsense · open source
Skills you'll practise
- Use the firewall log and state table to decide whether pfSense or OPNsense passed or blocked a connection
- Explain why a new block rule doesn't cut an existing connection and how to make it take effect
- Find rule mistakes: wrong interface, source port set, wrong protocol, NAT destination, netmask too wide
- Work through the port forward checklist using WAN and LAN packet captures and interpret the results
- Recognise asymmetric routing and harmless out-of-state log entries, and choose the documented fix
- Choose split DNS over NAT reflection and explain its one limitation
Course outline
- 1.pfSense and OPNsense troubleshootingVideo · 2 min
- 2.Is the firewall blocking it? Logs, states and rule mistakesLesson · 17 min
- 3.Port forwards that don't workLesson · 18 min
- 4.Captures, asymmetric routing and odd log entriesLesson · 15 min
- 5.pfSense and OPNsense troubleshooting: logs, states, port forwards, captures and asymmetric routing: knowledge checkKnowledge check · 17 questions
- 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- pfSense documentation: Troubleshooting Firewall Rules
- pfSense documentation: Troubleshooting NAT Port Forwards
- pfSense documentation: Troubleshooting Asymmetric Routing
- pfSense documentation: Troubleshooting Blocked Log Entries for Legitimate Connection Packets
- pfSense documentation: Packet Capturing
- pfSense documentation: Viewing the Firewall Log
- pfSense documentation: NAT Reflection
- OPNsense documentation: Rules (Troubleshooting section)
- OPNsense documentation: Log Files (Live View)
- OPNsense documentation: Diagnostics (Packet capture)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.