• MOVED: block the port in proxy

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Redirect SMTP and HTTP traffic with virtual IP from a specific source alone

    Locked
    23
    0 Votes
    23 Posts
    8k Views
    D

    Yep Eugene at last got it to work.. thnx for all the help.

    After adding DNS servers in the rule, it all started to work.

    Thanks,
    Venkat

  • Pfsense and MSN-proxy

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    Yes, we did and we have IMSpector installed as a backup solution now. But since the people who are going to menage the system are not too much the tech-inclined types, MSN-Proxy would give them a more user-friendly experience. That's why we're looking into it instead of using IMSpector.

    As for the problem, all logic applied looks correct. We'll keep on testing. Thanks for your reply.

  • Port Redirect with Public WAN and LAN

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    C

    You can setup port forwards just the same with public on both sides, I've done that a few times where someone wanted to send port 26 to port 25 on a public IP inside the network. The external and internal IPs are the same, just set the ports appropriately. That won't impact anything other than the specified external port.

  • Slow speed behind pfsense

    Locked
    10
    0 Votes
    10 Posts
    6k Views
    S

    Thanks all,
    I found it might be a MTU problem while I tuning the MTU down on mail server….

  • HTTP port forward not reaching web server

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    L

    Enable disable nat reflection and check windows firewall and antivirus firewall.

  • Outgoing Active FTP Problem

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A

    You know what?
    Thanks for making me do the TCPDUMP.

    Seriously.
    Because now I looked at its output, and I can see the problem:  The Userland FTP helper is working fine - but the connection on the client isn't being accepted.  Its the local client firewall blocking the active FTP incoming connection.

    I HATE ACTIVE FTP.

    But at least this problem is sorted.

    Thanks again!

  • Port forward problem

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    jimpJ

    Sounds like these:

    http://doc.pfsense.org/index.php/Logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection,_why%3F

    As Briantist proposed, those are very likely to be unrelated to the port forward not working. If it was, they'd be TCP:S, and no others.

    The OP may need to try to track down what is going on as described here:
    http://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

    Or it's also covered in the book.

  • How to set up Static/Persistent routes.

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    B

    So you're saying that you can successfully browse the web, etc, from 192.168.1.3 now? If so, then it sounds like all you need to do now is set up your firewall rules. On the interface where your public IPs lie (WAN?) you need to set up rules to allow the incoming traffic. The destination will be the LAN address and port(s). To see an example, add a regular port forward and let it generate the firewall rules automatically, then look at the rule it generates and use it as a guide.

  • DNAT only for specific IPs

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    A

    My problem is similar,

    I need to do DNAT on port 80 to a squid proxy (thereby making it transparent to the end users). But only for a specific IP.
    Both the squid server and the 'end users' are on the LAN subnet.

    Is this possible? In Linux iptables you would just to DNAT…..

  • Help! Esxi experts

    Locked
    12
    0 Votes
    12 Posts
    8k Views
    B

    hi xxsinxx,

    If you set the WAN interface on pfsense to one of your extra external IP's, say x.x.133.60/24 (because .59 is your vmware management IP) and you have the gateway set to x.x.133.254, then from within pfsense can you ping the gateway address? (diagnostics > ping > interface WAN > x.x.133.254)

    if you can ping then run a traceroute from the WAN interface to say Google DNS 8.8.8.8, if the hops don't get past your gateway you may have the wrong address as a gateway (or it's not properly routing your subnet/ip)

    if both of those respond properly then the problem is likely with the NAT/rules

    Hope this helps!

  • Active Directory Trusts behind NAT

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Issues with Nortel VPN client when behind pfSense NAT

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D

    Didn't say you had to post it, just look and see if there is anything there at all that might shed light.

  • [SOLVED] FTP server behind pfsense, cannot download from server

    Locked
    12
    0 Votes
    12 Posts
    6k Views
    B

    Setting the MTU on my WAN interface to 1496 fixed the problem.

    http://forum.pfsense.org/index.php/topic,13014.0.html

  • Nat/ Port forwarding issue

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D

    Is there a reason you won't just let the admin network access the access points directly?  I assume ADMIN is OPT1?  If so, it won't have any access to anywhere unless you add rules.  So, something like this:

    Firewall => NAT => Outbound:

    Enable Advanced Outbound NAT.  Add a rule that has a source subnet of the ADMIN subnet, and check the "No NAT" box.  In the rules section, add a rule applying to the ADMIN interface that only allows access to port 80 on the set of AP IP addresses (you can define those in an alias list elsewhere.)

  • No NAT forwards seem to work

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    A

    Thanks for your help GruensFroeschli, I've fixed it.

    The problem was a firewall. Disabled it and it's all working now so now all I need to do is configure rules.

    I thought wireshark captured before the firewall but it seems not.

  • 1 Interface needs to be NAT'd, one does not

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Manual Outgoing NAT problem

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Forwarding to Subdomains

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    S

    Will do, thanks :)

  • RemoteVNC Stopped working

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    Sadly that was not the problem.

    I change that checkbox and its no different then before.

    Just for fun, I changed back to automatic nat and it still does not work.

    Stupid Computer!

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.