Hey all. Newbie here, decided to start playing around in the homelab world so here I am. I picked up 2x R620s, a Brocade 6610 L3 switch, and a VMUG membership. I want to play around with vCenter, but when I went to install it, was notified that NTP needed to be set up. No problem right? Just ensure there's connectivity to the internet, right??
I want to be secure and play around with OPNsense / Grafana so I decided on trying to route all VM traffic (to include ESXI management traffic) through a OPNsense VM running in ESXI. Not sure if this is a good idea or possible but here we are. Anyway that idea led me to this network diagram. I mostly followed this guide (thank you for getting me this far Kapone). I feel like I'm almost there, OPNsense can ping 8.8.8.8 from both WAN and LAN interfaces, and it can see my ESXI host IP address 10.0.30.3. When I SSH into ESXI at 10.0.30.3 I can ping both OPNsense router interfaces (WAN and LAN), but not 8.8.8.8. In fact when viewing the live log in OPNsense, when I ping 8.8.8.8 (or 192.168.1.1) from my ESXI host IP, I see the packet going out passing through the firewall but nothing comes back. I can only assume 8.8.8.8 receives the ping but for some reason it's not getting routed correctly back to ESXI host all the way back through the network. There's gotta be a simple solution here. Here's my routing table in the brocade switch:
brocade#show ip route
Total number of IP routes: 6
Type Codes - B:BGP D:Connected O:OSPF R:RIP S:Static; Cost - Dist/Metric
BGP Codes - i:iBGP e:eBGP
OSPF Codes - i:Inter Area 1:External Type 1 2:External Type 2
Destination Gateway Port Cost Type Uptime
1 0.0.0.0/0 10.10.10.2 ve 2 1/1 S 1h7m
2 10.0.20.0/24 DIRECT ve 2 0/0 D 1h7m
3 10.0.30.0/24 DIRECT ve 3 0/0 D 1h11m
4 10.0.40.0/24 DIRECT ve 4 0/0 D 1h7m
5 172.16.0.0/24 DIRECT ve 1 0/0 D 1h7m
6 192.168.1.0/24 10.10.10.2 ve 2 1/1 S 1h7m
Here are my gateways on OPNsense:
Name Priority Gateway Monitor IP
WAN_DHCP (active) 254 (upstream) 192.168.1.1
LANINT 255 (upstream) 10.0.20.2
LAN_GW 255 (upstream) 10.0.20.1
WAN_DHCP6 (active) 254
Here's my routing table on OPNsense:
Network Gateway Description
10.0.30.0/24 LAN_GW - 10.0.20.1 MGMT to WAN
0.0.0.0/0 WAN_DHCP - 192.168.1.1
Here is my vSwitch topology for my LAN / Transit network
The only other thing I can think of is changing my TCP/IP stack on ESXI...but then again I feel like I'd break everything, because as of now ESXI can see both OPNsense interfaces...
Please for the love of god help me. I've been working on this for weeks. I've scraped this sub, servethehome.com forums, brocade forums, vmware help pages and forums, youtube videos...literally everything. I know my networking skills are lacking, but I feel like I'm *almost* there...thanks all.
I want to be secure and play around with OPNsense / Grafana so I decided on trying to route all VM traffic (to include ESXI management traffic) through a OPNsense VM running in ESXI. Not sure if this is a good idea or possible but here we are. Anyway that idea led me to this network diagram. I mostly followed this guide (thank you for getting me this far Kapone). I feel like I'm almost there, OPNsense can ping 8.8.8.8 from both WAN and LAN interfaces, and it can see my ESXI host IP address 10.0.30.3. When I SSH into ESXI at 10.0.30.3 I can ping both OPNsense router interfaces (WAN and LAN), but not 8.8.8.8. In fact when viewing the live log in OPNsense, when I ping 8.8.8.8 (or 192.168.1.1) from my ESXI host IP, I see the packet going out passing through the firewall but nothing comes back. I can only assume 8.8.8.8 receives the ping but for some reason it's not getting routed correctly back to ESXI host all the way back through the network. There's gotta be a simple solution here. Here's my routing table in the brocade switch:
brocade#show ip route
Total number of IP routes: 6
Type Codes - B:BGP D:Connected O:OSPF R:RIP S:Static; Cost - Dist/Metric
BGP Codes - i:iBGP e:eBGP
OSPF Codes - i:Inter Area 1:External Type 1 2:External Type 2
Destination Gateway Port Cost Type Uptime
1 0.0.0.0/0 10.10.10.2 ve 2 1/1 S 1h7m
2 10.0.20.0/24 DIRECT ve 2 0/0 D 1h7m
3 10.0.30.0/24 DIRECT ve 3 0/0 D 1h11m
4 10.0.40.0/24 DIRECT ve 4 0/0 D 1h7m
5 172.16.0.0/24 DIRECT ve 1 0/0 D 1h7m
6 192.168.1.0/24 10.10.10.2 ve 2 1/1 S 1h7m
Here are my gateways on OPNsense:
Name Priority Gateway Monitor IP
WAN_DHCP (active) 254 (upstream) 192.168.1.1
LANINT 255 (upstream) 10.0.20.2
LAN_GW 255 (upstream) 10.0.20.1
WAN_DHCP6 (active) 254
Here's my routing table on OPNsense:
Network Gateway Description
10.0.30.0/24 LAN_GW - 10.0.20.1 MGMT to WAN
0.0.0.0/0 WAN_DHCP - 192.168.1.1
Here is my vSwitch topology for my LAN / Transit network
The only other thing I can think of is changing my TCP/IP stack on ESXI...but then again I feel like I'd break everything, because as of now ESXI can see both OPNsense interfaces...
Please for the love of god help me. I've been working on this for weeks. I've scraped this sub, servethehome.com forums, brocade forums, vmware help pages and forums, youtube videos...literally everything. I know my networking skills are lacking, but I feel like I'm *almost* there...thanks all.