• OpenVPN Clients are not using outbound Port forwarding

    9
    0 Votes
    9 Posts
    614 Views
    DerelictD

    I have never seen that happen. a copied rule is the same as making a new rule. It is more likely you did not adjust something that needed to be adjusted.

  • Subnet NAT issue

    1
    0 Votes
    1 Posts
    277 Views
    No one has replied
  • having issues to SSH to Unraid Behind Pfsense Port Forwarding

    Moved
    7
    0 Votes
    7 Posts
    965 Views
    C

    thank your @Derelict your awesome thank you very much .. that worked

  • pfSense as OpenVPN client with both SNAT and DNAT

    4
    0 Votes
    4 Posts
    1k Views
    V

    I was talking about the rules on pfSense, of course.
    As mentioned, such traffic must not be handled by floating rules. I don't know if you've set up some.

    You may also do a workaround with an SNAT rule for that traffic on the Debian system to get the routing work. But maybe that's not the best solution.

  • Simple address forwarding

    21
    0 Votes
    21 Posts
    2k Views
    W

    @johnpoz said in Simple address forwarding:

    Your going to run into all kinds of problems trying to route stuff when the stuff is on physical and doesn't use pfsense as its gateway.

    If pfsense is not going to be a gateway to the internet then these networks do not even need to be wan.. 1 could be pfsense lan, and the other could be opt network.

    But according to the docs, WAN is required so is it possible to run pfsense with only LAN and OPT interfaces?

    On a separate note, when I cloned the VM, the MAC addresses changed. Can I control the assignment of which mac address is bound to em0 and em1?

    update on last week, I didn't have any virtual IPs since I wrongly figured the pfsense could see them both and ping them, but then once I added virtual IPs my 1:1 NAT forwarding started working.

  • Tried everything port forwarding not working??

    42
    0 Votes
    42 Posts
    6k Views
    D

    @johnpoz Thank you for all you help.

  • Hulu traffic

    3
    0 Votes
    3 Posts
    7k Views
    C

    Thanks for the tip! It appears this still works. Taking a slightly different approach worked for me, too.

    I have a dual WAN setup at home and use load balancing (round robin). 99% of services work just fine with this. But I was struggling with the "not at your home location" error on Hulu. I got around it by forcing auth.hulu.com and home.hulu.com traffic out my primary internet circuit. All other Hulu traffic seems to load balance just fine.

    If anything the suggestion above will work but you'll need to add the two new domains.

  • Portforwarding problem: https is working, http is not

    2
    0 Votes
    2 Posts
    407 Views
    R

    Resolved!

    It turned out to be a problem with the NAT outbound rules: By deleting the bridge (its name was set to "LAN") all outbound rules to the Wifi devices have been automatically changed to WAN (they were set to LAN before). However, after setting up LAN1 and OPT1, these rules have to be set manually to the right interface. It was just a coincidence that the https-device was still working as it does not need an NAT outbound rule.

    Thread closed ... :-)

    Regards,

    Volker

  • Port Forward Modem/Router and pfSense

    6
    0 Votes
    6 Posts
    831 Views
    stephenw10S

    DMZ mode, in everything I have seen, is like a 1:1 NAT rule. It forwards all traffic to whatever IP you nominate, in this case pfSense.
    So it removes the firewall for that IP but not for other IPs in the routers LAN subnet.

    Steve

  • Tks

    1
    0 Votes
    1 Posts
    212 Views
    No one has replied
  • Help with domain network behind pfsense

    11
    0 Votes
    11 Posts
    855 Views
    H

    Thank you johnpoz. I understand what you're saying.

  • Server Not Accessible from Internet (Port Blocked)

    5
    0 Votes
    5 Posts
    519 Views
    KOMK

    Normally you would have 2 vSwitches, one for WAN and one for LAN. Then you create a pfSense VM with two NICs, one on the WAN switch, the other on the LAN switch. You connect the WAN switch to your physical NIC and your VMs all connect to the LAN switch.

  • Private WAN IP and Private LAN IP

    8
    0 Votes
    8 Posts
    6k Views
    R

    @phil-davis
    Have the same situation even removing gw on lan doesn't work. Anything config needed on NAT.

  • NAT Outbound Separators (pls)

    13
    0 Votes
    13 Posts
    1k Views
    P

    @grimson @jimp true it would appear then that I'm going about this the wrong way. I will re-evaluate my NAT rules and firewall configurations

  • port forwarding not working

    3
    0 Votes
    3 Posts
    384 Views
    F

    fixed

  • FTP server backup WP - Can read but not write! (Local work perfect)

    4
    0 Votes
    4 Posts
    505 Views
    K

    Ok I set a SFTP server port 22. Do we need passive port for this too?

  • Set up a port forward, still not connectable

    5
    0 Votes
    5 Posts
    2k Views
    O

    Just FIY - there was some sort of a firewall running on the AP on the roof, and after contacting our ISP it was deactivated, and now it seems to work like it should.

  • NAT with IPSEC

    3
    0 Votes
    3 Posts
    424 Views
    N

    Thanks Steve !

    Will try to to nat in P2.

    cheers, pete

  • 1:1 nat and bridge on with 3 interfaces?

    4
    0 Votes
    4 Posts
    341 Views
    stephenw10S

    It would not necessarily show in the ARP table unless pfSense has been talking to it directly. The ISP would need to ARP for it and it back to the gateway but that is transparent through the bridge at layer 2.

    What exactly is not working? What is working? How are you testing?

    Steve

  • Redirect to wrong IP destination.

    7
    0 Votes
    7 Posts
    618 Views
    DerelictD

    If the wrong server is responding then the wrong server is responding to 10.0.20.7.

    Do a packet capture on the inside interface for connections to 10.0.20.7 TCP port 443.

    Test a connection in from the outside.

    Do you see the SYN going out the local interface? Is it destined for 10.0.20.7? What responds?

    You might need to look at the MAC addresses here to see what's really going on.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.