• Port forwarding not working from outside but works from the inside

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    Cry HavokC

    Please post a screenshot of your WAN firewall and port forwarding rules.

  • All incoming WAN traffic redirecting to port 443…

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    Cry HavokC

    Please post your WAN firewall and NAT rules

  • Drive failed, reinstalled/restored, now NAT doesn't work

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    J

    The output of "pfctl -sn" and "pfctl -sr" are identical for the two boxes, so the rules are being created correctly.

    I've tried a packet capture on the system that isn't working and this is what I get with Full detail.  Unfortunately, I've no idea what it all means.  IP addresses have been censored but otherwise the data is unmodified.  Traffic is from tcping on the port in question (ms-sql-s) but I tried a different port forward (https) and that isn't working either.

    09:56:25.709841 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 114, id 30438, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62525 > 208.176.yyy.zzz.1433: Flags [s], cksum 0xb5c6 (correct), seq 410772004, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:27.718749 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 113, id 30647, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62526 > 208.176.yyy.zzz.1433: Flags [s], cksum 0x6be1 (correct), seq 3962460245, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:28.706720 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 114, id 30650, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62525 > 208.176.yyy.zzz.1433: Flags [s], cksum 0xb5c6 (correct), seq 410772004, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:29.726159 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 113, id 30651, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62527 > 208.176.yyy.zzz.1433: Flags [s], cksum 0xe7e1 (correct), seq 2554933305, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:30.716128 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 113, id 30654, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62526 > 208.176.yyy.zzz.1433: Flags [s], cksum 0x6be1 (correct), seq 3962460245, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:31.736067 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 113, id 30657, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62528 > 208.176.yyy.zzz.1433: Flags [s], cksum 0x9363 (correct), seq 3848746904, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0 09:56:32.727035 00:21:62:94:fe:00 > 00:90:0b:11:57:2e, ethertype IPv4 (0x0800), length 66: (tos 0x0, ttl 113, id 30662, offset 0, flags [DF], proto TCP (6), length 52)     50.19.www.xxx.62527 > 208.176.yyy.zzz.1433: Flags [s], cksum 0xe7e1 (correct), seq 2554933305, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0[/s][/s][/s][/s][/s][/s][/s]
  • Port Sharing 80

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC

    Sorry, I use neither. Try asking the question in the Packages sub-forum.

  • NAT the same port for all gateways

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    C

    Thank you very much for your help.

    I have created a test rule based on instructions found in Docs, and it works OK, it just required a reboot of the Alix to work.

    I will post back if any other problem occur.

    Best

    Kostas

  • Upnp

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    M

    please help me to access my PublicIP with my upnp port from lan

  • Public adress on a client behind pfsense firewall

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G

    Hi, thanks for your answer.. i have one interface where my WAN is connected.

    What i did to make it work was that i added the public ip address as a virtual IP on the WAN interface.
    After that i added a 1:1 nat where the external ip was the public (ofc :-)) and the internal was the internal ip of the box i had on the inside.
    When that was done, i added a firewall rule to allow everything to the internal ip.

    That works…

  • My NAT acting more like a bridge than NAT [SOLVED]

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    I

    OMG - I'm such an idiot.

    I'm not sure why the default rules didn't work for me, but I figured out what my problem was.

    I looked at another pfsense install's default NAT rules and realized that the default outbound NAT rule for LAN to WAN is applied to the WAN interface…. (just like the hint says - Duh.)

    Anyway, I switched the rule from LAN to WAN... and it works exactly as I expect it would.

    Honestly, just explaining the problem on the forum helped me understand the problem enough to reach a solution on my own.  Thanks for just giving me a place to figure this out.. lol.

    I love pfSense. :)

    -Kevin

  • NAT Pfsense wan in other lan

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    I

    Hi Jannus,

    I think I'm having the same problem as you.  See -> http://forum.pfsense.org/index.php/topic,41743.0.html

    Did you ever get this issue resolved?  If so, what worked for you?

    Thanks!
    Kevin

  • Forwarding magic packet…

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • SSH using publickey not connecting after install 2.0

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Reflection question for 2.0-Release

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    P

    Yep, I've got a gateway set on my LAN interface and on my MNG interface (management vlan interface).

    Well, I wonder how this could have worked without breaking anything.

    I have removed both the default GWs leaving only one interface-bound GW on the WAN.

    Thanks for help!

    Peter

  • 2.0 How to redirect LAN port 80 to a proxy server

    Locked
    16
    0 Votes
    16 Posts
    43k Views
    jimpJ

    You cannot transparently proxy https.

  • NAT a hostname can I?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    Cry HavokC

    You can put a hostname in, and from memory (a search of the forum will tell you more) it is resolved every so often to see if it has changed.

    It may be simpler to use a VPN.

  • Help with Port Forwarding

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    P

    @tommyboy180:

    Pro Tip: If you create a NAT entry first a firewall entry will be created automatically for you by default.
    The pfsense GUI has a small learning curve. Most firewall distros don't have a separate NAT entry GUI than the firewall GUI.

    This only works for port forward NAT rules. With 1:1 NAT you still have to create the rules.

  • NAT only work in the PfSense BOX not other client in LAN [solved with 2.0]

    Locked
    33
    0 Votes
    33 Posts
    13k Views
    S

    Thanks all, the release version 2.0 has solved my problems…. =)

  • Need to connect via different subnet over IPSec VPN

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    D

    On the subject of NAT before IPsec VPN (not supported in pfsense 2.0), you can also read http://redmine.pfsense.org/issues/1855

  • 1:1 NAT in 2.0 Release, display incorrect IP on outbound connections

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    G

    I created the ip as a virtual ip and not in 1:1 and then created NAT rules, and set the outbound nat accrdong to the need I had. It did work AFTER i rebooted the ISP modem in this fashion. I suspect it will also work in 1:1 as well. I feel like there should be a big fat sticky note somewhere on 1:1 and modems and arp (as in sticky or note in the pfsense gui)…

  • Asterisk running ON pfSense2.

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    B

    marcelloc> very interesting, I'll dig into that!

    Now everything is ok, calls in all directions…fine tuning on: voicemail,codecs order, redirection,call transfert, pickup call...

  • How to create NAT for block of IP's?

    Locked
    15
    0 Votes
    15 Posts
    5k Views
    M

    create proxy arp or virtual ip for every single ip you have.
    1:1 transfer any trafic but only one client/server(unless using server loadbalancing)
    with portforward you can decide what trafic you want to server have and can use multiple servers(ex. port 80 -> server1, port 25 -> server2 etc.)

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.