• Setting up PFSense on a VM and allowing access to the webConfigurator

    3
    0 Votes
    3 Posts
    423 Views
    N

    Ok, so in this configuration it seems that the best solution is to create a second VM running on the same physical NIC as the LAN connection. I launched a Fedora VM, configured a second NIC reaching to the first VM as the gateway and immediately gained access to the webConfigurator.

    Anyone have an idea as to why this doesn't work from the host machine?

  • How To NAT FTP IIS on Windows 2012R2

    1
    0 Votes
    1 Posts
    359 Views
    No one has replied
  • Fragmented IPv4 UDP not NAT'd on WAN

    2
    0 Votes
    2 Posts
    359 Views
    S

    Hi,

    While I have found a work-around in this particular instance - by reducing the header information in the SIP request, anyone sending UDP out on a WAN with a lower MTU than the LAN might run into this issue. This might affect VPN links as well as VOIP. Typically intranet LANs run 1500 byte MTU and VDSL/Fibre can often have a slightly smaller MTU.

    If you do have an issue with WAN outbound UDP, running tcpdump on the WAN leg and loading the file into wireshark to look for the source address being transmitted out of the firewall.
    0_1537861986638_b7c16e8e-6480-442a-a494-9ccc0254be79-image.png
    If you see the LAN source address, then you have the issue.
    There may be a config setting that will change the behaviour, however if this cannot be found,the packets will be dropped by the first internet router that sees them as private non-routable addresses are just that.
    Regards
    Simon

  • 0 Votes
    1 Posts
    380 Views
    No one has replied
  • 2nd router behind pfsence. Strict Nat.

    2
    0 Votes
    2 Posts
    447 Views
    T

    I figured it out. I needed to use 1:1 NAT for the routers ip.

  • 1:1 NAT vs Outbound NAT

    4
    0 Votes
    4 Posts
    713 Views
    S

    The 1:1 page is for the inbound connection.

    It can get crossed up if you do that manually, so traffic comes in one IP and the reply is sent out another. That generally doesn't work since the other end drops the reply packets.

    I'm pretty sure pfSense will just automatically do it right. If you can connect out from the servers using 1:1 then connect out to whatismyip.org or something and you can see what IP you're connecting out on.

    On the outbound page what I was trying to say was that any rules entered there are processed in order, like firewall rules.

  • Voip with NAT

    1
    0 Votes
    1 Posts
    362 Views
    No one has replied
  • TCP retransmission

    1
    0 Votes
    1 Posts
    628 Views
    No one has replied
  • Port forwarding stopped working

    10
    0 Votes
    10 Posts
    927 Views
    M

    Ok, I found the problem. It was the internet gateway or upstream(as you said). I reinstalled the OS and the exposed host function worked again. For some reason it still shows 0 opened port, but hey it works! Thanks for your quick and professional help!

  • Having problems redirecting ports with NAT

    2
    0 Votes
    2 Posts
    341 Views
    DerelictD

    Your rules have to pass traffic to 192.168.1.11 not WAN Address.

    Not sure how you ended up there considering you have Add associated filter rule selected and it most certainly would not create a rule like that.

  • Question about reflection

    1
    0 Votes
    1 Posts
    392 Views
    No one has replied
  • SIP traffic getting hijacked by router

    7
    0 Votes
    7 Posts
    1k Views
    DerelictD

    If you are interested I can provide a secure upload link outside of the forum.

    I generally like to see the exact rules that cause unexpected behavior. Kind of like seeking closure and understanding.

  • AWS 1:1 NAT

    4
    0 Votes
    4 Posts
    661 Views
    J

    @derelict appreciate the response. A second reading of your comment straightened me out. Your kind hand holding has earned netgate a customer!

  • TCP doesn't work through 1:1 virtual IP

    2
    0 Votes
    2 Posts
    567 Views
    DerelictD

    How about you pose all of those screenshots instead.

    @mars said in TCP doesn't work through 1:1 virtual IP:

    1:1 Virtual IP to LAN IP 192.168.7.100
    Outbond 192.168.7.0/24 * * * Virtual IP public *

    I do not know why you would do this. 1:1 means just that. 1:1. It looks like you are also trying to outbound NAT the whole /24 to the same VIP which should work fine. But I honestly do not know what would happen in that case.

    @mars said in TCP doesn't work through 1:1 virtual IP:

    WAN rules IPv4 TCP/UDP * * ->LAN Net * *

    This also makes little sense.. You should be passing traffic to 192.168.7.100, not LAN net.

  • Cannot resolve locally hosted tld's when connected to Openvpn

    2
    0 Votes
    2 Posts
    347 Views
    E

    Enabling NAT Reflection fixed my issue.

  • NAT for transparent Solved

    7
    0 Votes
    7 Posts
    1k Views
    K

    Thanks that did the trick on the shared frontend had to add that and on the redirect to HTTPS sections Thank you so much

  • UPNP glitch when adding VPN

    1
    0 Votes
    1 Posts
    285 Views
    No one has replied
  • PBX NEC Sv8100 nat 5060 port

    3
    0 Votes
    3 Posts
    810 Views
    C

    I found the solution with this rules :

    0_1530282966474_fcfe0fcc-c0bd-4fef-8c62-7f79c5065c3c-immagine.png

    ![0_1530282975934_043c27f8-c900-4e0c-becc-c156505b4d32-immagine.png](Caricamento 100%)

    Thanks ...

    Andrea

  • Port forward issue

    21
    0 Votes
    21 Posts
    2k Views
    D

    @johnpoz said in Port forward issue:

    @valnurat said in Port forward issue:

    I have been told that I can't do a port forwarding if I don't have a static IP. Is that true?

    Where exactly are you getting this nonsense??

    In our community where I live.

  • [Solved]pfSense 2.4.3 Port Forwarding problem

    19
    0 Votes
    19 Posts
    4k Views
    T

    Ok, i don't know what happened but i switched the WAN interface with another physical interface and it started working.
    At this point i thank you for helping me so much and i'll mark this thread as solved.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.