• Plex with OpenVPN

    6
    3
    0 Votes
    6 Posts
    1k Views
    G
    @mathais Have you looked into using a solution like Tailscale to make this work? It should be able to traverse your VPN regardless of how NordVPN has it set up... Setting up what Tailscale calls a "subnet router" in your network and changing your Plex settings to work with webview through this server... obviously you need to run tailscale clients on your devices that want to access your Plex server. https://community.umbrel.com/t/how-to-run-plex-through-tailscale/14595
  • IP unit without default gw - nat/portforward/…?

    4
    1
    0 Votes
    4 Posts
    546 Views
    rmathisenR
    Thanks a lot for the help @JOHNPOZ, now I got it working :-)
  • Need help - verifone credit card machine

    2
    0 Votes
    2 Posts
    615 Views
    GertjanG
    @vada123 said in Need help - verifone credit card machine: It fails immediately, which indicates to me that it is being blocked somehow. Or : traffic never reaches pfSense. @vada123 said in Need help - verifone credit card machine: I have looked through the firewall logs and there are no entries for the ip of the PC or the verifone Get back to the default state of the credit card reader : it's probably "DHCP". Power down PC and credit card reader. Now : look at the pfSense Status > System Logs > DHCP log page. Start up your PC, credit card reader etc. You should see lines like this : [image: 1707980843001-7bdf357c-df4e-4055-b0ca-104f775fdbc9-image.png] where the MAC is the MAC of the device you've switched on. "igc1" is the interface on which pfSense received the DHCP request. This is the interface on which a pfSense DHCP server should be running. Remember : at this stage the device hasn't an IP yet. These DHCP packages are not fire-walled (if you have a DHCP server set up - on LAN, by default, you have one). So : again : traffic reaches pfSense ?
  • how to configure OpenWRT router after pfsense box?

    Moved
    4
    1 Votes
    4 Posts
    1k Views
    buggzB
    Thanks for all the replies! I have FINALLY gotten one of my OpenWRT devices to work. Now to replicate to other devices. I am finding my problem is from tinkering with too many things at once.
  • Trouble with nat/portforward/(maybe)vlan to game servers

    2
    0 Votes
    2 Posts
    517 Views
    I
    I didn't change anything and today went to sanity check some things. Tried logging into the servers to see if pfsense had any logs relating to it and they both just work now?? Anyone know why?? I'm very confused :/
  • It works now??? Anyone know why?

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • Port forwarding to OpenVPN tunnel

    7
    1
    0 Votes
    7 Posts
    3k Views
    T
    @viragomann oh yes, good point. I was confused by the fact that many times the NAT device is also the default gateway, so the masquerade is not needed. But it is not my case with openvpn. Many thanks again for explanation and support.
  • 1:1 Nat only works in one direction

    3
    0 Votes
    3 Posts
    453 Views
    S
    @milonic Did you mean to use 10.1.1.1/24 for the VIP?
  • As of 2.7 explicit rule needed for reply packets from inbound NAT?

    1
    0 Votes
    1 Posts
    156 Views
    No one has replied
  • How do port forward negations work with 1:1 NAT?

    6
    0 Votes
    6 Posts
    684 Views
    DerelictD
    @senseivita Still no way to know why you are experiencing issues looking at that rule set. With the 1:1 in place you need to pass the desired inbound traffic to 10.7.0.229 and 10.16.0.35. Like I said, port forwards, by default, make this rule for you. 1:1 NAT does not.
  • GRE Tunnel possible NAT setup

    2
    0 Votes
    2 Posts
    608 Views
    A
    Fix to Issue Issue was NAT was being applied to local LAN and remote LAN which need to be removed. This is automatically created with pfSense by default. Disabled NAT under Firewall>NAT> Outbound change to Manual Outbound NAT rule generation. (AON - Advanced Outbound NAT) Then select the NAT Rules to disable for Tunnel Interface for local LAN and remote LAN, then click on Toggle button to disable rules. Done
  • Port Forward 80 Webserver

    26
    0 Votes
    26 Posts
    3k Views
    S
    I have been doing a little more digging and the issues I am facing seams to be common with the 2.7.2 release. There's loots of threads over on redit so I'm convinced that SOMETHING has changed within this release because NOTHING about or with my setup has changed.
  • NAT Problems

    3
    1
    0 Votes
    3 Posts
    390 Views
    S
    @viragomann Thanks a lot!
  • 0 Votes
    4 Posts
    551 Views
    V
    @louis2 said in 1:1 NAT reflection to replace splict DNS as solution to reach my own public servers from the LAN: However since DNS query's are more and more hidden in HTTPS, Split DNS solutions do not work any longer. So I need a different solution, which might simplify things as well. You should better care, that the local devices use your local DNS instead. Normally you can configure web browsers to not use DoH, but the system DNS resolver. And for the hard cores, there are lists with DoH servers in the internet, which you can use to block it. option: System > Advanced on the Firewall & NAT Enable automatic outbound NAT for Reflection I combination with some rules in "Firewall NAT1:1" This should also enable internal devices accessing your public IPs without additional NAT rules. But remember, this is only NAT as well. When a packet is arriving via the WAN, the WAN has a couple of rules to allow / to block / to NAT. When using NAT 1:1, you have to additionally configure the necessary firewall rules on WAN and on the internal interface. The NAT rules don't pass any traffic on their own.
  • 2 WAN interfaces toubleshooting on Azure

    4
    0 Votes
    4 Posts
    442 Views
    V
    @ddave421 Yes, this one. But this ist Just an additional IP on the NIC.
  • Using NPt seems to have a strange interaction with some LAN devices

    1
    0 Votes
    1 Posts
    223 Views
    No one has replied
  • OpenVPN NAT to IPsec

    8
    0 Votes
    8 Posts
    678 Views
    D
    @viragomann Okay, it doesnt work. My setup. Firewall Site A: Openvpn remote net to 192.168.123.0/24 and 172.16.0.0/24 Firewall Site B: Openvpn local network 192.168.123.0/24 172.16.0.0/24 On the virtual IPs Ive added every NAT IP Address as /32 for example 10.123.1.23/32 The rules are from Site A 10.1.0.0/24 -> Site B 192.168.123.0/24 * Site A 10.1.0.0/24 -> Site C 172.16.0.0/24 * The Firewall Site B: have defined a Outgoing NAT for connections coming from 172.16.0.0/24 to 10.1.0.23 by using a NAT with the NAT IP 10.123.1.23 And a port forwarding in the other direction. Thats an example setup for one site with one ip. But is that connect ? I cant reach the site a from site c with this setup.
  • Firewall blocking Synology MailPlus Server

    12
    1
    0 Votes
    12 Posts
    1k Views
    S
    @aquinch Hello! Are you running the traceroute while shelled into your DS? I get flaky results running traceroute with the port option while shelled in. You could try a different host and run putty/telnet... telnet mail.synology.com 25 telnet mail.synology.com 587 ... John
  • OpenVPN or NAT?

    5
    5
    0 Votes
    5 Posts
    417 Views
    V
    @thewho Glad that you it working.
  • Setting Custom NAT Protocols in newer PF versions

    2
    0 Votes
    2 Posts
    445 Views
    B
    Nevermind, I guess. Looks like no one knows. In the meantime I figured out a different way as workaround.... hand editing the Backup NAT and Firewall rules and using Restore. Just export, copy your last rule from each, paste into a new one. Change the name, blank the associated GUID ID to nothing, change protocol to ipencap, blank the port in port reference. Save. Import NAT file. Import Firewall file. No reboot needed. Do a tcpdump -vvv -i tunl0 on your NAT'ted AMPR gateway you're trying to expose. If you did this right and AMPR portal is already sending traffic to your public IP, your NAT should kick in and ipencap should start flowing and registering on your terminal from tcpdump immediately. Good luck if youre on newer PFsense.. (2.7.2) looking into running AMPR gateway, and Google brought you to this post. Cheers Byron
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.