• All external attempts to SSH or SFTP yield "connection refused"

    6
    0 Votes
    6 Posts
    486 Views
    P
    First, thanks for the reads and comments. It seems that, upon seeing my WAN Address as 172 and not my IP that something was fishy with the modem. Either ATT or a power cycle reset the modem to block traffic and not pass it all to PFSense. I changed that setting, and we are back in action. I'm sorry to have wasted your time on this, as I assumed my settings on the modem were unchanged.
  • Check 1 to 1 Nat public ip, returned internal ip address

    1
    0 Votes
    1 Posts
    172 Views
    No one has replied
  • 0 Votes
    3 Posts
    343 Views
    A
    Hi @netblues, thanks for your response. I agree it would be much easier if I connected to the VPS PFS from the VLANed VM. But the thing is I want to know how to make this using PFS. So let's start with some questions, as I might have gaps of knowledge: Peer-to-Peer (Site-to-Site) OVPN connections: are they bidirectional? If I wanted to NAT Port Forward to this Interface which 'Redirect target IP' should I use? thanks
  • FTP not working

    6
    0 Votes
    6 Posts
    523 Views
    Raffi_R
    @Napsterbater said in FTP not working: @anakaoka I have LONG LONG abandoned IIS FTP. I have used Filezilla FTP Server for quite awhile Though it has no capability to use AD/LDAP for user auth. But it does support Implicit and Explicit TLS for FTP, Passive and Active FTP and IPv6. For Passive FTP, just configure a range of Ports and forward those the to server, and configure the External IP in the Server settings. Second this ^ Filezilla was my solution for a while also. It worked great and did exactly this with a range of passive FTP ports. Eventually ditched that Windows system and created a FreeNAS server with secure FTP access similar to the Filezilla. FreeNAS is pretty awesome stuff.
  • NAT subnet from BGP route

    3
    0 Votes
    3 Posts
    350 Views
    E
    I ended up re-designing how the neighbors interacted and eliminated the need for another set of routes from a second AS. I think one of the IP pools was in conflict, that's no longer the case :)
  • NOT DOES NOT WORKING PARA PORTAL HTTPS

    1
    0 Votes
    1 Posts
    138 Views
    No one has replied
  • NAT / Port forward to IPsec tunnel

    1
    0 Votes
    1 Posts
    209 Views
    No one has replied
  • Are the Autocreated ISAKMP rules needed?

    10
    0 Votes
    10 Posts
    8k Views
    jimpJ
    @powerextreme said in Are the Autocreated ISAKMP rules needed?: Also, why is the loopback address using ISAKMP? It normally isn't, but it's included in the networks for automatic outbound NAT rules, and each entry in that list gets the udp/500 static port rule.
  • Port forwarding from Virtual IP

    3
    0 Votes
    3 Posts
    395 Views
    T
    That's what I needed. Thanks.
  • 0 Votes
    1 Posts
    221 Views
    No one has replied
  • 0 Votes
    7 Posts
    581 Views
    A
    @netblues said in Multiple virtual IPs, one WAN -- outbound round robin use of IPs possible?: @Airwave and consider random with stickiness since changing ip's between https requests tend to break things badly. Okay, great thank you. I'll test these options :-)
  • Hairpin nat for a test environment

    1
    0 Votes
    1 Posts
    239 Views
    No one has replied
  • 0 Votes
    3 Posts
    344 Views
    SipriusPTS
    So, after a some CSI I notice that inbound packages where reaching the target machine, the problem was that the Firewall B didnt knew where to sent back the response, so I added a new rule in NAT Outbound for this particular device, and worked like a charm: [image: 1595436390941-0d66b8df-182e-417f-b492-f56c1d24b4d4-image.png] NOTE: Firewall B doesnt use Firewall A gateway, its a "hybrid" VPN.
  • Upnp Port Forwarding question

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • Simple internal NAT - Can't port forward on internal LAN

    9
    0 Votes
    9 Posts
    689 Views
    johnpozJ
    @bgillette said in Simple internal NAT - Can't port forward on internal LAN: well i had my NAS admin exposed so i could access it remotely Would never in a million years expose nas admin to the public internet.. If you can not lock down forward to a known source IP, say your work, or where you remotely admin from.. Then VPN into to do your remote administration.
  • NAT Reflectiion Two WAN's

    2
    0 Votes
    2 Posts
    392 Views
    H
    Perhaps use proper DNS instead?
  • NAT rule enabled on another interface than specified

    10
    0 Votes
    10 Posts
    577 Views
    johnpozJ
    Hmmm, what was system default set too? Mine is disabled - but it defaults to what pure nat or nat+proxy? I really don't see how that would of come into play on a different interface.. Can try and duplicate it - what setting did you have in system, and can set mine to that and then look at the exact rules being created..
  • Access Back-haul Radios

    37
    0 Votes
    37 Posts
    26k Views
    O
    @hotshottech said in Access Back-haul Radios: I got it going…..here are the rules that got me there. Thanks guys for all the help....see attached [image: Post2.png] [image: Post2.png_thumb] [image: post3.png] [image: post3.png_thumb] Hi! I also have a same problem... ISP Router Modem (DHCP) 192.168.2.1-RADIO(192.168.30.X)-RADIO(192.168.30.Y)-PFSENSE(192.168.2.1) sadly, can't see the attached files...
  • Forward fragmented UDP (SIP) traffic

    2
    0 Votes
    2 Posts
    189 Views
    mike1818M
    @mike1818 (Replying to my own post) There is a problem with the PABX. Retried it and saw outgoing traffic from the pfSense to the PABX which is acting like there is no traffic. Sorry for bothering.
  • Private WAN IP

    5
    0 Votes
    5 Posts
    466 Views
    S
    Thanks, I'll write tomorrow as I check it out.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.