• Port-Fowarding question with Layer 3 switch as router

    3
    0 Votes
    3 Posts
    579 Views
    DerelictD
    Yeah. No difference. Just port forward to the inside address. As long as the target host's reply traffic makes it back to pfSense it will work.
  • 1:1 more then 4 ip

    2
    0 Votes
    2 Posts
    511 Views
    johnpozJ
    If you want to use your /26 behind pfsense why would you not just have it routed to you?  Then you wouldn't have to nat even you could put these machines on that netblock and just firewall. Why don't you sniff and validate traffic hits your wan, and is sent on out to the machine..  If traffic is sent on to the machine and it doesn't answer then issue is on the machine - firewall common problem, different gateway another common problem, etc.
  • SIP and PBX port Forward

    1
    0 Votes
    1 Posts
    478 Views
    No one has replied
  • Automatic outbound NAT rules and GRE

    3
    0 Votes
    3 Posts
    777 Views
    V
    Can anybody answer this? Does it seem reasonable to have a checkbox for every gateway providing the possibility to exclude that particular gateway from automatic outbound NAT rules? Or perhaps have such a checkbox for GRE interfaces only?
  • Port forwarding Public IP to a private IP on a VLAN

    4
    0 Votes
    4 Posts
    2k Views
    C
    Nevermind… something happened on the windows box and i had allowed RDP through the windows firewall previously for "Work" network's, but now it's identifying as public.
  • Intermittent Port Forwarding

    1
    0 Votes
    1 Posts
    515 Views
    No one has replied
  • NAT rule not working between LAN and LAN

    6
    0 Votes
    6 Posts
    911 Views
    johnpozJ
    Dude if you have some downstream router that understands this 10.96.0 network then you would create a static route.. Still not understanding where this 10.96.0 network is… its on your VM host? your 192.168.1 is a transit to get to this downstream network.  If your doing some nat on some VM host.. You would send traffic to this VM hosts IP where this IP is natted too..
  • Softether VPN + pfSense - how to connect it?

    2
    0 Votes
    2 Posts
    908 Views
    V
    UP No idea guys?
  • External Connection Times Out to Gateway IP

    1
    0 Votes
    1 Posts
    434 Views
    No one has replied
  • PfSense locks up when using virtual IPs with NAT

    1
    0 Votes
    1 Posts
    416 Views
    No one has replied
  • 0 Votes
    2 Posts
    482 Views
    KOMK
    What network is your WAN on?
  • Local VOIP - no incoming calls

    2
    0 Votes
    2 Posts
    608 Views
    A
    Delete all the rules you created for SIP/RTP then start analyzing your SIP traffic.
  • Plex remote access

    2
    0 Votes
    2 Posts
    788 Views
    C
    here is mine i can access plex remotely ![Capture (2).JPG](/public/imported_attachments/1/Capture (2).JPG) ![Capture (2).JPG_thumb](/public/imported_attachments/1/Capture (2).JPG_thumb) [image: Capture3.JPG] [image: Capture3.JPG_thumb]
  • NAT rules vs firewall rules

    2
    0 Votes
    2 Posts
    702 Views
    johnpozJ
    When you create a port forward, the default setting is to auto create the firewall rule on wan for you to allow.. If you have rules ahead that specific block other than the default deny then that could fail - and you would have move the wan allow for your nat to be above any explicit blocks of the ports your wanting to forward inbound.
  • Problem with NAT port web server. Please help me!!!

    6
    0 Votes
    6 Posts
    821 Views
    M
    Thanks you. everything was ok when I switch to mode NAT + Proxy Originally I chose the mode Pure NAT Thank so much
  • Nat from LAN to LAN

    2
    0 Votes
    2 Posts
    3k Views
    V
    Forwarding is no solution here. That translates the destination address to another one, however, your crap device won't work with that, since the source address is out of another subnet. What you need here is translating the source address into one out of the subnet of the concerned device and which is assigned to the pfSense interface, so that responses are sent back to pfSense. That can be achieved by outbound NAT in pfSense. Firewall > NAT > Outbound If the outbound NAT is still working in automatic mode, select the hybrid mode and save that setting first. Then add a new rule. According to your example, select the VLAN30 interface (the interface facing to the problematic device), at destination enter 10.10.30.200, at translation address select "interface address" which is the default value. Save it. Accessing the device should work now.
  • DNS load balancing

    2
    0 Votes
    2 Posts
    686 Views
    jimpJ
    The DNS load balancing feature doesn't see much testing, it's possible there is an issue there, or it may just be a limit of relayd. Last time I tried it, it worked, but I also wasn't trying to have it hit a different internal port. How are you testing it to see if it works? Have you tried other monitoring types than ICMP? One major thing to be aware of, when relayd does dns balancing it acts like a proxy, so your DNS servers will only see the address of the firewall itself and not the clients. Depending on your DNS server config that may make a difference in how it handles the queries.
  • VALID NAT POOL

    4
    0 Votes
    4 Posts
    815 Views
    T
    Thanks for the responses! Will be trying out the following as suggested by jimp: The above on WAN, plus y.y.y.0/30 routed to x.x.x.2, then set y.y.y.0/30 as an outbound NAT subnet"
  • [SOLVED] Unable to ping from LAN network to other subnet

    4
    0 Votes
    4 Posts
    658 Views
    V
    :D I'm Austrian. The 35C3 is to far for me to got to.
  • Pass original SMTP source IP to mail filter inside LAN

    15
    0 Votes
    15 Posts
    1k Views
    S
    It is working now.  The windows box at that IP had it's subnet mask set to 255.0.0.0 in stead of 255.255.255.0.  Not sure why.  I changed it to 255.255.255.0 and I can access that machine through the vpn with that outbound NAT rule disabled.  Thanks for your help on this.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.