• NAT Reflection Pure NAT quick question

    2
    0 Votes
    2 Posts
    598 Views
    DaddyGoD
    @xlameee said in NAT Reflection Pure NAT quick question: Is this rule open port to outside that can be exploit ? Hi, Every port you open on the firewall compromises the security of your infrastructure... yet often inevitable what I would advise you that, you are not the only one who knows the basic ports of known applications, the scanners know them well whenever possible configure the application for a non-basic port, drop the port to 40-50K range Forget http if possible and go to https - or use a proxy
  • Cannot create outbound NAT rules in Hybrid Outbound NAT mode

    4
    0 Votes
    4 Posts
    810 Views
    johnpozJ
    @swordforthelord said in Cannot create outbound NAT rules in Hybrid Outbound NAT mode: helpful error message, You mean like this [image: 1637416461771-likethis.jpg] If I try and create outbound hybrid nat with range like 3000-3100 I get that error..
  • Strange NAT behaviour

    1
    0 Votes
    1 Posts
    479 Views
    No one has replied
  • pfsense plus on AWS

    virtual ip nat aws
    1
    0 Votes
    1 Posts
    697 Views
    No one has replied
  • Alias + FQDN IP resolution

    1
    0 Votes
    1 Posts
    429 Views
    No one has replied
  • Nat forwarding not able to work

    1
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • IPSec tunnel not connected due to double Nating

    1
    0 Votes
    1 Posts
    424 Views
    No one has replied
  • NAT Source Allow Rule not working

    7
    0 Votes
    7 Posts
    1k Views
    johnpozJ
    @steveits oh man you beat me to it - but I got in a picture ;) hehehe edit: Oh wait I beat you, heheheh
  • DMZ 1 firewall vs DMZ 2 cascaded firewalls

    3
    0 Votes
    3 Posts
    822 Views
    B
    @johnpoz thank you, is clear. im expecting a 6 port device to arrive for this configuration. If i have any questions i will post again. Thank you.
  • LAN>Internet>WAN

    6
    0 Votes
    6 Posts
    738 Views
    I
    @johnpoz Many thanks) Compared the settings of both Pfsense - NAT Reflection was disabled. I set the Nat + Proxy mode, everything worked. Thanks again!
  • OpenVPN to internal network NAT

    nat
    3
    0 Votes
    3 Posts
    929 Views
    S
    @viragomann Thank you for your reply. The lan interface gateway is empty and the NAT is set in 'Manual Outbound NAT rule generation'. In any case I found the problem, there was a NAT rule configured to a network interface group with the LAN interface included. Avevo controllato many time NAT configuration! Thank you very much!
  • External Access (PIA VPN & Port Forwarding)

    2
    0 Votes
    2 Posts
    529 Views
    L
    Okay, as it always is. As soon as I post a question I figure out the problem HAHA My problem was I didn't forward correctly from my "modem/router". In the UK we have modem/routers handed out by BT (as an example). Previously I setup a DMZ to solve this issue but I forgot to update the IP on that. Now I've updated it, everything is working as expected.
  • Port forwarding/NAT from VPN to local server

    10
    0 Votes
    10 Posts
    2k Views
    HostilianH
    @bob-dig said in Port forwarding/NAT from VPN to local server: with them in the first place? Ahhh. OK. Thanks. Yes, some servers allow it. One of them happened to be one I used, but switched from, due to speed issues. These speed issues are everywhere though - so I may switch back to the Windows client and Wireguard. Pretty crap, but it's that slow (to PIA) I have just about written OpenVPN off.. OpenVPN (using PFSense) is about 1.5MB/s. Using PIA Client in Windows - Wireguard - is easily over 10MB/s. Thanks for your time and information guys. Appreciated!
  • Services Cannot Reach Each Other on Same Server!

    5
    0 Votes
    5 Posts
    715 Views
    A
    @viragomann Yep, that’s definitely the difference. Upon switching, most of my network broke and it’s been challenging getting each piece back to function. However, it’s been an excellent learning experience. I think this issue may relate to a concession I made to fix a different problem. Thanks so much.
  • NAT on specific port

    11
    0 Votes
    11 Posts
    1k Views
    R
    @viragomann Confirm. Green flag and it says port is open on public ip address. I'm going to check the device. It should be the oroblem Maybe it's not responding correctly.
  • 1:1 NAT to OpenVPN 2.5.0

    9
    0 Votes
    9 Posts
    2k Views
    A
    @cibiri Hi! Can you post your config? I'm trying to translate with the newest pfsense but the interface changed and it's not really working When I configure my nat rule (10.0.64.0 first IP will translate to 192.168.0.0/18 (the overlap)) - my site 0 is 172.x and all my clients (15 of them) are 192.168.0.0/18 ) binat on openvpn inet from 192.168.0.0/18 to any -> 10.0.64.0/18 I;ve also configured OPT1 but nothing. But it's not working. Any other config somewhere I'm following this tutorial https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-nat-subnets-conflict.html
  • Routing public IPs without NAT

    1
    0 Votes
    1 Posts
    330 Views
    No one has replied
  • Outgoing NAT for single Host

    5
    0 Votes
    5 Posts
    765 Views
    DerelictD
    @volans But they become actual IP addresses on the firewall which is unnecessary for NAT purposes. Making individual "Other" /32 VIPs will add them to the menus too without doing that. That's probably a GUI defect. This was already found and fixed in 2.6.0 snapshots.
  • NAT / reply from unexpected source

    4
    0 Votes
    4 Posts
    991 Views
    V
    @jpgpi250 It's to be set in Firewall > NAT > Outbound. If your Outbound NAT is working in automatic mode switch to the hybrid mode first and save it. Then add a new rule like this: interface: this one which is facing to the monitoring / client protocol: TCP/UDP source: the clients subnet dest: the monitoring IP dest. port: 53 translation: interface address
  • Nothing under Automatic Rules: for Outbound NAT

    3
    0 Votes
    3 Posts
    770 Views
    artooroA
    @viragomann you're amazing. I guess somehow the WAN was configured without selecting the gateway. This solved the issue. At least hopefully the next person coming across missing NAT rules will find this post in their search results.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.