• Mail server connection from NAT to port-forward

    10
    0 Votes
    10 Posts
    2k Views
    M
    @viragomann @JeGr @Derelict thank you, the traffic redirect works like a charm :) Thanks again for your time and patience !
  • nat reflection on opt interface

    2
    0 Votes
    2 Posts
    290 Views
    V
    Try the "NAT + proxy" mode or set up split DNS instead.
  • IPSEC and NAT / NAT OVER OTHER SUBNETS

    1
    0 Votes
    1 Posts
    217 Views
    No one has replied
  • Nat Redirection Issue.

    2
    0 Votes
    2 Posts
    154 Views
    johnpozJ
    I would suggest you troubleshoot the port forward like you would any other https://docs.netgate.com/pfsense/en/latest/nat/port-forward-troubleshooting.html But here I just setup your exact rule.. And works just fine. [image: 1570788414936-otherport.jpg] Also!!!! I would not suggest you open remote desktop to the public, even if using a different port.. If you want to rdp to your machines from the outside - vpn would be the more secure option. At a min you should lock it down to only known source IP that you would be using. I had this open for like 10 seconds, just long enough to test it and show you that can work.. Not that its a good idea to ever do such a thing. You understand that windows remote desktop has had multiple security issues, has been all over the news as of late with remote access issues. https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/rdp-security-explained/
  • Quick NAT/OpenVPN questions.

    7
    0 Votes
    7 Posts
    603 Views
    RicoR
    I'd recommend everyone using a VPN Provider with pfSense to watch https://www.netgate.com/resources/videos/openvpn-as-a-wan-on-pfsense.html -Rico
  • Port forward to an address behind another router

    solved
    10
    0 Votes
    10 Posts
    3k Views
    G
    @johnpoz You are 100% correct. pfSense can port forward at any subnet behind other routers as NAT and Routing tables are correct. The problem was on my ISP and the new Public IP he gave me which was blocked in inbound traffic. SOLVED. Thanks a lot for your time.
  • NAT Question / Problem

    1
    0 Votes
    1 Posts
    221 Views
    No one has replied
  • Xbox Double Nat issue

    1
    0 Votes
    1 Posts
    302 Views
    No one has replied
  • private ip for WAN , public ip for LAN

    6
    0 Votes
    6 Posts
    564 Views
    DerelictD
    @joregartinez You can use it just like that I think with the /29 configured on your DMZ interface. In that case, you would probably want to disable NAT for it (enter hybrid NAT mode and put a NO NAT rule for the /29 there.) Binding services on the firewall itself (Like a VPN Server) should be able to be told to listen on the DMZ address, but I can think of things the system is going to do that will break that, like the host route to the other side. You might need a VIP on the WAN for that. Outbound NAT for connections from the firewall itself should be able to be told to use the DMZ address as well using manual outbound NAT but I have never tried that. Seems it should work just fine but you might hit some kind of route-to weirdness I'm not thinking of. But if you have a VIP on the WAN for service binding you might as well just use that. It is generally a bad idea (as in it breaks things) to NAT connections from the firewall itself and from the WAN address. You will want to do exactly that, though. If you do put a VIP on the WAN make it a /32. Note that hosts on the DMZ will not be able to access that VIP because they will not know it is not on their local subnet.
  • Logging WAN outbound question

    13
    0 Votes
    13 Posts
    2k Views
    DerelictD
    Again, the solution lies in marking traffic as it enters the firewall and matching that mark on its way out WAN.
  • NATing behind IPSec Vti Tunnel

    6
    0 Votes
    6 Posts
    516 Views
    DerelictD
    https://forum.netgate.com/post/489029 The diagram is down below. There are two. That was written against the one with the blue symbols. The version of pfSense there is old but the principles haven't changed.
  • Active mode ftp trouble

    4
    0 Votes
    4 Posts
    444 Views
    L
    @Lazer13 said in Active mode ftp trouble: Wan ip to DMZ ftp port 21 This one has been removed for testing but still no go. I also removed the openvpn server. No difference
  • Rounter via OpenVPN with PIA as service provider

    openvpn routing
    2
    0 Votes
    2 Posts
    523 Views
    S
    Just realized that i posted in the wrong section - going to repost in the right section.
  • SNAT between LAN interfaces

    7
    0 Votes
    7 Posts
    977 Views
    johnpozJ
    Great - glad you got it sorted.
  • Manual outbound NAT for High available sync

    1
    0 Votes
    1 Posts
    210 Views
    No one has replied
  • NATing a single interface

    4
    0 Votes
    4 Posts
    460 Views
    J
    @Derelict nevermind i understand what you mean now. I can have a gateway just don't assign it under the interface settings itself...
  • Port Forward multiple ports to a specific port

    3
    0 Votes
    3 Posts
    524 Views
    A
    Should be pretty simply, actually... First of all, you need to setup an alias for ports 14000 - 15000. See attachment: [image: 1569594604613-screen-shot-2019-09-27-at-9.29.00-am.png] Then make a port forward on the appropriate interface (I used WAN in the example), using your alias from above as the destination port: [image: 1569594874117-screen-shot-2019-09-27-at-9.33.36-am.png] Enter the IP address of your server in the "Redirect target IP" box. Let the NAT auto-create the firewall rule, see the bottom of the window, it says "Filter Rule Association". Make sure it says "Add associated filter rule" That's all you have to do in pfsense. Make sure your server is set to listen on port 13000, and if there is a built-in firewall, like in Windows, it is set to allow traffic thru. If this is passing traffic thru the internet and your ISP, you should also make sure your ISP allows ports 14000 - 15000 to pass to you. If they block, you will never get this to work. Jeff
  • SG-3100. Port Forwarding

    Moved
    7
    0 Votes
    7 Posts
    699 Views
    D
    @kiokoman Thank You, I now see what I may have done. Sincerely Thanks
  • send packets out the same interface it arrived on

    3
    0 Votes
    3 Posts
    385 Views
    T
    Bull's-eye. The answer I was looking for. Thank you @viragomann very much
  • Port forwarding does not work when I use my ISP's nat?

    2
    0 Votes
    2 Posts
    395 Views
    JKnottJ
    @Ivan007 Welcome to one of the "benefits" of NAT. When you set up port forwarding on your firewall and have a public address on the WAN side, the traffic from the web site can reach your firewall, where port forwarding is used to send it to a specific computer. When the ISP puts NAT ahead of your firewall, there is no way for you to configure port forwarding on it, so there's no route to your firewall. NAT is a hack to get around the IPv4 address shortage and it breaks somethings Port forwarding is a way around one of the things it breaks, that is transparency along the entire path. With ISPs NAT you can longer work around it. This is why the world MUST move to IPv6 as soon as possible. The more NAT is used, the more things break. Already with VoIP and some games it is necessary to use STUN servers, to get past NAT. I don't know that those will still work behind ISP & customer NAT combined.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.