Remote Shack with Expert Remote 

'all-in-one-place' practical setup guide
4.3.6 It just require one more modification: click in 'pen' of the 'Interface VLAN50_DHCP Gateway' to enter edit mode, check Upstream gateway, uncheck Disable Gateway Monitoring, enter 1.0.0.1 in 'Monitor IP', Save and Apply:

This completes entire basic configuration of the opnSense in context of this guide. The WAN/LAN setup is now ready. To validate you can configure your laptop to use 192.168.16.1 as default GW (do not forget DNS servers 1.0.0.1 or 1.1.1.1)

and go to Expert Cloud to validate:

Security considerations
At this stage you do not need to create or modify any firewall rules - those already automatically created by opnSense, reflecting all configured interfaces. "Zero trust" policy automatically applied on all WAN inbound traffic, that means no connection allowed from external, unless it was requested from internal. This already existing configuration is more than sufficient for Remote Shack operations.
At later stage you may review the firewall rules and create new, if needed; or you can add VPN, etc. This need to be done carefully evaluating what you configure: for example limiting Starter to only connect Expert Cloud sounds secure, but this will stop TURN traffic. Hence - consider futher reading opnSense documentation and ask the community.

BACK     NEXT