• My own web not visible…

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    Thanks.. it worked :D
  • NAT and Rule problems

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    D
    Ah… When I put on a unic VHID Group on every carp IP everythig was ok... :-)
  • NAT not working, already used search

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    K
    Becouse i want to disable NAT on router, maybe all port forwarding to pfsense wan interface wont make sense. If helps: [image: pfwanint.jpg] [image: pfrouter.jpg_thumb] [image: pfnatfor.jpg_thumb] [image: pfnatfor.jpg] [image: pfnatout.jpg_thumb] [image: pfnatout.jpg] [image: pflanint.jpg_thumb] [image: pflanint.jpg] [image: pfwanint.jpg_thumb] [image: pfrouter.jpg]
  • Squid with nat

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    U
    thanks for reply. i wait 1.3 release with impatient.
  • NAT 1:1 only for outbound, standard port forward for inbound help

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    P
    when Server A (192.168.4.250) tries to connect somewhere its "public" ip shows up as 200.200.200.250 However when someone tries to connect to 200.200.200.250 the port forward should route any packets on ONLY port 80 to Server B (192.168.4.240). technically if i were to 1:1 nat when someone connected back to 200.200.200.250 it would get sent to 192.168.4.250 and not to 192.168.4.240 and thats the problem :/ If i understand you correctly you want the VIP 200.200.200.250 to point to LAN IP 192.168.4.240 and the only thing you haven't done so fare is setting up NAT -> Outbound -> Manual Outbound NAT WAN  192.168.4.240/32  *  *  *  200.200.200.250  *  NO
  • Problem with NAT port forward

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    GruensFroeschliG
    Well to be honest i find it a bit strange that you have a subnet of 10.0.0.0/8 on your LAN, and at the same time traffic destined for 10.0.0.0/8 should be sent to a gateway. To me this seems a bit conflicting. I mean if something is in the same subnet than the interface itself this means you shouldnt have to send it to a gateway because it's directly reachable.
  • FTPS cannot get through

    Locked
    9
    0 Votes
    9 Posts
    9k Views
    J
    Do you know some possible things to look for that would interfere with this working? We have dual wan. We have multiple FTP servers tied to different virtual ips.
  • passing NATTed traffic over IPSec: HOW?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG
    I'm not sure i really understand what you are trying. But you cannot NAT traffic into a IPSEC tunnel.
  • NAT Firewall problem Showing Internal IP to Public Program

    Locked
    10
    0 Votes
    10 Posts
    5k Views
    N
    Just wanted to let everyone know it wasn't a Pfsense problem, but a Barracuda Webfilter that was causing the problem, still not sure how, but it was the problem.
  • Bridge with transparent web proxy? Possible?

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    C
    I only have the backend code which has to be applied to the firewall at every reboot. I dont write interface gui code. But I can walk a coder to what needs to be done in the gui to make it work with the backend. Until someone is willing to do ti its not worth my time and effort to do so.
  • NAT a /25 IP Block

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    GruensFroeschliG
    Well you could do it like this: Internal net: 10.1.1.128/25 External Net: 192.168.1.128/25 translates to 10.1.1.192/26  to  192.168.1.192/26 10.1.1.160/27  to  192.168.1.160/27 10.1.1.144/28  to  192.168.1.144/28 10.1.1.136/29  to  192.168.1.136/29 10.1.1.132/30  to  192.168.1.132/30 10.1.1.130/31  to  192.168.1.130/31 10.1.1.129/32  to  192.168.1.129/32 like this you dont have to create 125 rules but only 7
  • VOIP- strange problem with incoming

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Nat address pool

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    J
    @tdickson: I would love to use this feature to get around - or mitigate PPTP issues. fricken seems to have hit a wall (either that or I can't figure it out)  and I have 90 public IP's I would love to randomize to help with PPTP connections… You said you can set it up non-GUI?  I've been searching around, and this post (with no answer) is about as accurate as I can come by. Any pointers are more than welcome. have you managed to get this to work? I'm looking into doing the same thing…
  • Multi Public IP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • NAT LAN to OPT1

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG
    Yes. Search the forum for Advanced outbount NAT. EDIT: sorry i just realized that LAN per default gets NATed to all Interfaces. You shouldnt have to create any AoN rules. It should just work.
  • Assign computers behind pfsense to WAN interfaces

    Locked
    14
    0 Votes
    14 Posts
    6k Views
    L
    I am still getting this problem, I don't know if anyone can help…
  • Outbound NAT port change problem

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Is this configuration correct??

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S
    Thats very enlightening, it looks like that should do the trick, but it doesn't want to cooperate. I also tried static DNS mapping while I was at it and if I tried pinging the host in question, it would show the ip address I mapped statically, but the ping would time out. This made me wonder if I had a firewall rule stopping traffic from flowing, but I tried a basic config with all interfaces allowed to pass all traffic to  all other interfaces (all wildcards), but still nothing. For now I'm content to use the local ip of the server when on the LAN, it's not that big a deal to have to remember. Thanks for the help though!
  • MOVED: Cannot connect to a game.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • SSH dropping with NAT reflection

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    A
    Ah, including SSH in the search term was showing other irrelevant postings.  Thanks for pointing me to those. To summarize for people who run into the same search pitfall: If you are running 1.2RC3 or later, adding the following tag to the <system>tag within config.xml will increase the timeout: <reflectiontimeout>3600</reflectiontimeout> where 3600 is the number of seconds worth of timeout. James</system>
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.