• XBOX 360 open NAT HowTo for pfSense 1.0?

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    M

    @bobvan:

    On one hand, I like the UPNP approach because it should only open what's necessary when it's necessary.  On the other hand, it's a license for any rogue bit of malware on my network to open anything it wants.  (Thankfully, I seldom run Windows.)  If I get UPNP working, I should probably add firewall rules that allow only the XBOX to talk to miniupnpd.

    This is a common misconception that doesn't stand up to analysis.

    The fact is, if you have malware on your network, on a typical firewall it's fully capable of opening up any outbound connections it wants. UPnP does allow it to open up inbound ports too, but only in a limited way. Is there anything that can be done with a upnp inbound connection that couldn't, technically, be done through an outbound connection? No. In fact it's probably far easier and less likely to be detected (and certainly more reliable) for malware to create vulnerabilities through initiating outbound connections and local network sniffing.

    The reality is in a lot of cases UPnP is a lot more secure than alternatives like static inbound mappings as the ports are only opened when required. They are also (if the upnp IGD is capable) loggable and monitorable.

    Sure, you don't want UPnP on a typical corporate network, but there's certainly a big place for it on home networks and even SME networks.

    Cheers,

    Keith

  • Getting to the external IP & portfowards from inside.

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    H

    @mickrussom:

    Is there a way for the public to file bugs?

    You can create bug tickets at http://cvstrac.pfsense.com/ but pleaso only file tickets when you are absolutely sure that you found a bug in the LATEST version or after you have been told by one of the devs to create a ticket. First discuss at forum or mailinglist to make sure the problem is not caused by misconfiguration or whatever.

  • FTP not working on bridged connection

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D

    Problem solved. Thanks

  • Access Dyndns Adress from Lan

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    Make sure your dyndns update was successfull. Also are you talking about portforwards you created at WAN or to access directly to the pfSense? If you try to reach portforwards you need to enable nat reflection at system>advanced (very bottom of the page).

  • OPT1 not able to hit WAN

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H

    Do you see the traffic being blocked at status>system, firewall? Also what gateway do the clients at the bridged OPT1 use?

  • Can't connect to ftp

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    P

    Yep, that fixed it, thanks :)

  • 1:1 NAT problem

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    i have proxyARP virtual IPs. i couldn't configure basic port 22 forwarding from
    ProxyArp ip into OPT1 interface.
    i need 1:1 NAT anyway and it is working now including ping (ICMP).
    How does it work? or it shouldn't work and I have to use CARP?

  • Reflection without router-ip?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    Use a split DNS setup.

  • NAT issue with RC3e

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    B

    ygm

  • FTP Passive Private IP Translation To Public

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    R

    Nevermind…. When I first tried this I didn't have pasv_address defined at all in the config. pftpx does translate it. I set pasv_address=10.10.1.15 the internal ip and it works great both internal and external.

    Confusing as I swear it didn't work before.

  • Nat and dmz help

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    So is your bogus bug report.

  • Bridging problem

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    B

    FYI, Enable filtering bridge is now checked, and rules added for the OPT1 interface. Everything seems to be working fine now… What a headache...

  • Simple NAT problem

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    H

    Yes, that was fixed.

  • NAT question, how to NAT internal subnet to another…

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    S

    i will try to get more information from them, maybe they can clear this up.

    thanks for your help!

  • Hide NAT

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    H

    Looks like you rather want a multiwan setup than some freaking nat settings. I suggest searching the forum as this is a hot topic at the forum. Additional to this you can use advanced outbound nat to make some special things working (if it doesn't work right after setting up multiwan).

  • Force port on email server

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S

    No documentation yet on this, feel free to write some.

  • FTP Server reachable through OPT1

    Locked
    23
    0 Votes
    23 Posts
    10k Views
    H

    Dear Tomba,

    you are setting things up wrong. I have FTP as well as other services working at OPT-Interfaces forwarded from WAN and I also configured an FTP-Server for someone at IRC that was reachable from OPT-WAN.

    I suggest you get to IRC this evening and try to contact me there. We can try to make it work together by remote administration.

  • Dual firewalls, dual wan, carp - only one wan failing over properly

    Locked
    12
    0 Votes
    12 Posts
    6k Views
    B

    @BugeyeD:

    i see BLOCK/DROP rules here, none of which are being logged. i do understand why they are there and what they are trying to protect against. what i noticed as being odd was that WAN (em2) is not represented here, whereas OPT1 (em1) is. so naturally i have to wonder if packets are getting dropped at OPT1 and not on WAN, thus breaking failover on OPT1 but not on WAN. but since logs are not being generated i can't tell for sure.

    updated to the new snapshot, still have the same situation and therefore the same question.

  • Quake 4 or game servers behind pfSense

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    M

    I updated to this latest snapshot and then tried to monitor my server via Server Watch
    and Qtracker and it still can't connect to it. It appears as though it is still not reflecting
    the UDP correctly at least for Quake 4.

  • Port forward NAT + accessing NATed Services

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H

    You always need a VIP to make use of additional IPs on an interface. It won't work without. This is something that is different from m0n0.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.