• Point to Point video call

    6
    0 Votes
    6 Posts
    2k Views
    J

    You should read this post reading H.323 behind PFSense.

    https://forum.pfsense.org/index.php?topic=54800.0

  • Modem Access with OpenVPN

    4
    0 Votes
    4 Posts
    801 Views
    M

    @Derelict:

    If I had to guess, it is not OpenVPN that's the problem but the introduction of policy routing.  See if this doesn't have the information you need to fix it:

    https://doc.pfsense.org/index.php/Bypassing_Policy_Routing

    This was exactly it, and after getting it setup, makes total sense. Thanks for information. Much easier than I thought it would be.

  • Web hosting behind pfsense

    4
    0 Votes
    4 Posts
    3k Views
    M

    Your DNS for your LAN connection is either non-existent or misconfigured. The easiest thing to do would be to set your pfSense machine as a DNS forwarder and create a static entry for your web server (eg www.domain.com) so that your LAN users will be able to access your web server from it's internal address. I'm assuming your web server is sitting on your LAN or a DMZ. Consult this link for more info: https://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F

  • Configuring 1:1 for funky ISP redirection of static block

    2
    1 Votes
    2 Posts
    564 Views
    R

    The error had to do with a rule on my other firewall. 1:1 with Proxy ARP did the trick.

  • Noob question about NAT

    3
    0 Votes
    3 Posts
    773 Views
    G

    Thank you!

    That's exactly what i was looking for.

    It works fine now

  • NAT reflection and slow outlook

    3
    0 Votes
    3 Posts
    984 Views
    M

    Ive now set internalhostname to real internal hostname. Its ok now.

    But can anyone explain it to me, why are things so drastically slow when you use NAT reflection?
    It shouldn`t be in my opinion…
    I still think that I maybe have some config error somwhere, in my home enviroment with same exchange settings things work just fine...

  • Two devices, same ports to be forwarded

    5
    0 Votes
    5 Posts
    1k Views
    johnpozJ

    Pretty sure xbox will use UPnP to open ports in a firewall.

    What exactly are you trying to stream from?  How do you get xbox to connect to this stream?  Why don't you sniff on the lan of pfsense and then try and connect to your stream..  What do you see?  Does it try and use multicast to discover the streamer?  Or do you direct it to an ip of the streamer?

    Your scenario is exactly what UPnP can help get around - be it with no security involved.. UPnP from a security aspect is an abomination..  But most clients should ask the firewall hey I want port X sent to me.. Firewall can say sorry that is in use by another client - pick something else, etc.

    Why don't you just grab multiple wan IPs and then setup 1:1 nat for these IPs to your devices on your private lan segments as another option.  Setting up that many ports in a Forward on a shared wan IP that is natted is going to break nat at some point..  Since your severely limiting the ports that can be used for the napt function.

  • MOVED: Isolar o acesso a 2 redes distintas instaladas no pfsense

    Locked
    1
    0 Votes
    1 Posts
    417 Views
    No one has replied
  • Extra public IPs not working

    4
    0 Votes
    4 Posts
    935 Views
    C

    Whether or not VIPs are required depends on your ISP's setup. If they're routing them to you, no need for VIPs. Where you must answer ARP on them, you must have a VIP type that answers ARP. Where you have multiple aliases on the same device, they all show up as the same MAC. Outside of circumstances like CARP, VRRP, and HSRP that use virtual MACs, there is only one MAC on a given interface and all the IPs on that interface use it.

  • How to create a Virtual IP address pool for use with outbound NAT?

    3
    0 Votes
    3 Posts
    4k Views
    J

    I do this on several firewalls.  It is pretty easy to do.

    First, create the virtual IPs.  In my case, I have a /24 that I use most of for a round robin NAT pool.  I proxy arp these IPs.  The /24 is subnetted into smaller blocks so I can carve out the other IP's I need for other services.

    Then just create outbound NAT rules.

    Remember to set the pool options in the rule, such as round robin, RR w/ sticky address, etc…

    ![nat outbound alias.PNG](/public/imported_attachments/1/nat outbound alias.PNG)
    ![nat outbound alias.PNG_thumb](/public/imported_attachments/1/nat outbound alias.PNG_thumb)
    ![nat blocks alias.PNG](/public/imported_attachments/1/nat blocks alias.PNG)
    ![nat blocks alias.PNG_thumb](/public/imported_attachments/1/nat blocks alias.PNG_thumb)

  • 1:1 NAT onto Bridge

    2
    0 Votes
    2 Posts
    653 Views
    S

    Hmm.  After looking further, the 1:1 NAT appears to not be working, even without the bridge configuration.

    For now, disregard this request.  I can create a new topic later if I cannot find a solution.

  • Port 443 open

    24
    0 Votes
    24 Posts
    5k Views
    G

    @doktornotor:

    @muswellhillbilly:

    According to MS it's to do with performance: http://windows.microsoft.com/en-gb/windows7/stream-your-media-over-the-internet-using-windows-media-player.

    Ah of course, who gives a fuck about security, performance is much more important in the MS land; plus it's extremely excellent idea to steal standard HTTPS port for some media streaming junk.  :o ???

    lol..so true!

  • Help Nat alias /24

    7
    0 Votes
    7 Posts
    1k Views
    DerelictD

    I thought they had to match.  Learned something new today.

  • NAT and aliases

    9
    0 Votes
    9 Posts
    1k Views
    D

    Do as you wish.

  • Pppoe over USB NIC

    1
    0 Votes
    1 Posts
    676 Views
    No one has replied
  • Multiple WAN-ip: Use Virtual IP or use second network adapter?

    1
    0 Votes
    1 Posts
    530 Views
    No one has replied
  • SIP Protocol

    6
    0 Votes
    6 Posts
    1k Views
    KOMK

    the phone should contact the server without any NATING on the WAN side ?

    No, NAT is happening regardless.  The server talks to the phone via the WAN IP address, and pfSense tracks and translates that to the LAN IP address of the device.

  • Port Forwarding is failing

    14
    0 Votes
    14 Posts
    2k Views
    C

    Really need to describe your setup a bit more. It doesn't sound like you want or need to do any port forwarding here. But it's not clear what you're trying to accomplish.

  • MOVED: Pfsense behind adsl router - IDS problem

    Locked
    1
    0 Votes
    1 Posts
    435 Views
    No one has replied
  • Poor VLAN and NAT Performance

    11
    0 Votes
    11 Posts
    3k Views
    K

    Yes, it's definitely a Xen problem.

    Now I have a giant question: how to have many and many isolated networks on the same Xen and pfSense interfaces? VLANs were the "traditional solution". Other than subnetting each server /30 with dedicated gateway, obviously…

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.