• Help with port forwarding Minecraft server

    8
    0 Votes
    8 Posts
    3k Views
    johnpozJ

    your interface is lan - that is wrong.. Your forward interface would be wan!!

  • 1:1 NAT = No Internet

    2
    0 Votes
    2 Posts
    1k Views
    DerelictD

    1:1 takes precedence over outbound NAT.

    You are probably going to have to post what you have done instead of a description of that you think you have done.

    We have a 2nd Static Block coming through same WAN (182.x.x.x /28). Not sure where to configure except as a Virtual IP which I have yet to do

    Is that routed to an address on 70.x.x.x /28 or is it somehow on the same interface.

    If it is routed you can do anything you want with it. Use it as VIPs. Put it (or a portion of it) on an inside interface, disable NAT, and assign addresses from it directly to inside servers. Route it (or a portion of it) somewhere downstream.

    If it is not routed and you are not yet using it, I would ask them to change it. There are no downsides and lots of upsides to having a routed subnet.

  • Local site with wan access

    4
    0 Votes
    4 Posts
    590 Views
    NogBadTheBadN

    Watch this and change rdp to http :-

    https://www.youtube.com/watch?v=1LM6PdwSAaY

    If your external ip address starts 192.168.x.x your ISP is handing out rfc1918 private IP addresses for your WAN so NAT would be taking place further up the chain.

  • 2nd LAN Interface to WAN

    3
    0 Votes
    3 Posts
    764 Views
    R

    Thanks for your help!

    @viragomann:

    Nothing. WAN net ist the subnet configured on the WAN interface, not the whole internet. WAN address is the WAN interface address.
    The whole internet is "!(RFC 1918 networks)".

    So add all the addresses you want to permit access to an alias and use this in a pass-rule as dest.

  • NAT External IP Rotation

    3
    0 Votes
    3 Posts
    1k Views
    K

    What about a script to change the Address Pool every X hours?  Then I can have 1 Subnet active per hour and rotate them through each.

  • Is this double NAT?

    13
    0 Votes
    13 Posts
    2k Views
    JKnottJ

    I am on tmobile phone and it doesn't get an IPv4 any more just IPv6.

    Mine too.  My cell carrier uses 464XLAT to provide IPv4 support.

    Giving a school back in the day when internet first started a /8 was not forward thinking ;) heheh

    Of course, that predated personal computers, tablets, cell phones etc.  The 32 bit addresses were intended only to be for a demonstration, with larger addresses when "officially released" at least according to Vint Cerf.

  • WAN IP change does not clear NAT/firewall states

    1
    0 Votes
    1 Posts
    493 Views
    No one has replied
  • NAT over IPSEC

    5
    0 Votes
    5 Posts
    1k Views
    A

    Hi Derelict,

    Thanks for chiming in.

    Yes, I was experimenting with the Phase2 settings and was able to make things work!  :)

    Thanks again everyone for your thoughts and suggestions.

    pfSense rocks!

    Cheers,
    Armen

  • Home ISP dmesg: arp <hw>is using my IP address <ip>on</ip></hw>

    2
    0 Votes
    2 Posts
    1k Views
    J

    Yeah. AT&T are idiots who do 802.1x authentication of their gateway, so you can't even buy a standard VDSL modem or hook up your own router to the ONT (Fibre)

    Their IP pass-through mode still subjects you to NAT table limitations and that like, unfortunately. And I recall reading something about blocked ports.

    I read something about extracting the certificate and the private key from the AT&T gateway with an exploit. Obviously not endorsed by AT&T though.

    This looks interesting. I don't have AT&T so I can't comment but it might work. Don't know if pfSense has an ebtables equivalent.

    http://blog.0xpebbles.org/Bypassing-At-t-U-verse-hardware-NAT-table-limits

  • Forwarding port 80 - lan side issue (link with pictures) [SOLVED]

    1
    0 Votes
    1 Posts
    487 Views
    No one has replied
  • Connection Issues

    6
    0 Votes
    6 Posts
    1k Views
    A

    Ok, removing the source port numbers has made mail flow, however i still get no mail to my android unless disconnected from the wifi…. Suggestions?

    Also my computer tells me i have no internet access, in network & Sharing Center, as well as on my task bar??? I do have network connection, it just says i don't???

    ![network connection.PNG](/public/imported_attachments/1/network connection.PNG)
    ![network connection.PNG_thumb](/public/imported_attachments/1/network connection.PNG_thumb)
    ![network connection2.PNG](/public/imported_attachments/1/network connection2.PNG)
    ![network connection2.PNG_thumb](/public/imported_attachments/1/network connection2.PNG_thumb)

  • 0 Votes
    1 Posts
    435 Views
    No one has replied
  • MS Office365 behind pfsense

    1
    0 Votes
    1 Posts
    422 Views
    No one has replied
  • On interfaces and NAT

    1
    0 Votes
    1 Posts
    462 Views
    No one has replied
  • Replacing router using Pfsense and 2 NICs

    2
    0 Votes
    2 Posts
    511 Views
    V

    If the modem already does NAT you will have a private IP address on WAN. If so, you have to uncheck "Block private networks" in the WAN interface settings to permit incoming connections.

    Also consider that you need to set a firewall rule to allow incoming traffic as well. This may also be done in the NAT rule by the "rule association" option.

  • OPT1 can't get Internet

    12
    0 Votes
    12 Posts
    2k Views
    N

    Normally that happens when you are at full multitasking with just one core processor (head)…  :)

  • VOIP works on old firewall, broken under pfsense

    3
    0 Votes
    3 Posts
    837 Views
    DerelictD

    All the phones are on the same subnet with the voip server (192.168.10.0/24).  The voip server is static on 192.168.10.15.

    That is same-subnet traffic. The firewall is not involved other than, perhaps, as a DNS and DHCP server. Probably going to have to be more specific about what is or is not working.

  • 0 Votes
    1 Posts
    360 Views
    No one has replied
  • Port Forwarding pfSense and Synology VPN

    1
    0 Votes
    1 Posts
    896 Views
    No one has replied
  • Moving from Cisco ASA

    7
    0 Votes
    7 Posts
    1k Views
    B

    Glad to get it sorted out !

    Thanks for your help dotdash

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.