• Yet another NAT problem thread

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J
    that fixed it, thanks man :)
  • Forwarding a port with a destination of pfsense IP

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    F
    Hello I have tried that but doesnt seem to be working see my picture for how its setup in the port forward page [image: portforward.jpg] [image: portforward.jpg_thumb]
  • Yet another NAT issue :: nothing seems to work

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S
    Thanks to cmb and mrzaz for the response. Now that I have checked from an outside host, I seem to be able to browse the web server – which I couldn't from inside, which means redirection is working. Also, I didn't know that they could be handled in such a different way in PF -- apparently a lack of experience with that. But that solves the trouble for the time being. Thanks for the links to pf doc, I'm reading it at the moment. Thanks again. Regards
  • Port forwarding

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    The port forward needs to be on WAN, not OPT1.
  • 1:1 NAT Problem - LAN->WAN=OK, WAN->LAN=OK, LAN->VIP->LAN=BAD

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    H
    Ok.  I added a rule to forward port 80 and that works great!  Thanks! But I don't know all of the ports that need to be forwarded.  Ideally everything.  I see that reflection is limited to <501 ports. Note: Reflection only works on port forward type items and does not work for large ranges > 500 ports. Can you recommend a better approach to solving this? Thx
  • FTP Proxy from special port

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Reg Https website access

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    dotdashD
    firewall, rules, lan: tcp,lan net,,,443-https,wan-gateway Make sure this rule is before the default that point to the load balancer. Better solution is to make a balancer pool and a failover pool. point to the failover for https, point default to balancer.
  • VoIP issue with remote phone

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    Update - since what I have been reading pointed to the issue being resolved with AON I decided to try it.  I kept the default wan rule and added a copy of it pointed at opt1 (wan2).  After resetting the states and waiting a short period of time I tested the remote phone and it is working perfectly now. Thank you for a great product!!!
  • NAT port forwarding dilemna from pfsense noob

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    J
    First off, let me change my subject line for this post to "NAT port forwarding stupidity from no common sense BOOB". Cry Havok patiently asked me what the default gateway was for 192.168.XX.10. The answer?  THE WRONG ONE.  It was set for 192.168.XX.1!!!  Upon changing it to 192.168.XX.2 (the LAN for my pfsense box), everything worked just like it's supposed to. I should be embarrassed (and I am).  ::) Thanks to all who replied, especially Cry Havok, who helped me trip over the obvious!  It's always the little things…
  • Strange outgoing FTP traffic

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    P
    sorry i forgot to add those details i am using 1.0.1 built on Sun Oct 29 01:07:16 UTC 2006 and it runs on a dedicated x86 pc with 3.2ghz and 1gb ram.
  • Nat reflection timeout

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Use WAN portforwardings to DMZ from LAN..possible? - SOLVED

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A
    It worked, thanks :)
  • NAT-T support?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C
    We did, but it wasn't the transparent change we'd hoped for. It broke IPsec, so it was pulled. It's too late in the release cycle to mess with it. 1.2 will not support NAT-T, though it may be added as a package maybe by the end of the year. 1.3 will support it.
  • Problem with forwarding (nat reflection)

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    F
    Getting from the inside. No luck :/ :/ why redirect goes to 127.. ?? tcp 127.0.0.1:19004 <- 87.205.173.90:3000 <- 10.0.209.55:1797 FIN_WAIT_2:FIN_WAIT_2 tcp 127.0.0.1:19004 <- 87.205.173.90:3000 <- 10.0.209.55:1800 FIN_WAIT_2:FIN_WAIT_2 Getting from the outside (everything OK - ShieldsUP test) Redirection OK. tcp 10.0.209.5:3000 <- 87.205.173.90:3000 <- 4.79.142.206:40384 SYN_SENT:ESTABLISHED I have Nat Reflection Unchecked. Does not work with checked either :( Before updating to 1.2rc2 It worked without unchecking that option.
  • An odd (NAT?) problem, could use some help figuring this one out!

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    GruensFroeschliG
    I set it up that i only have the ports unscrambled that i need unscrambled. For that let the default scrambling rule be and create above the default rule a rule for your single port you want to have unscrambled. rules are processed from top to down and if one rule catches the rest is no longer considered. Do you mean it does not scramble them when you NAT them to be accessed from the outside? This is a different matter. This is about OUTBOUND NAT. All ports on outgoing connections get scrambled (even Bittorrent, look at the state tables while you are downloading). But some Programms get their destination to send the reply to, from the source port out of the header of the packets they recieve (with the correct scrambled port) and thus work.
  • Carp type vip and nat

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Multiple WAN addresses

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    GruensFroeschliG
    You dont have an AON rule for your global scope. I dont think that you can route out the WAN without NAT.
  • Help w/ NAT for FTP

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    N
    Thanks :) It's works here too :p Thanks tlsail for your screenshots :)
  • Can't ping from OPT1 to internet, but can resolve names

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    N
    OK, I think I got it!  Through setting my outbound advanced NAT mappings for each interface with a rule of source any, * * *, etc.. and enabling the filtering bridge in the advanced setup, it all worked!  Granted, traffic seems to be flowing through my LAN interface rather than WAN, but I can sort that out later (this is on a test network with a software router on my mac so… ;) ).  So thanks!!! NickZ P.S. I've attached a screen-shot of my routes-table here. [image: routes.png] [image: routes.png_thumb]
  • Fios Static IP and pfsense - Can't access internet.

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    G
    Well I took your advice and verified that I was told to use the wrong IP for my gateway.  I'm still trying to wrap my head around the fact that my Linksys running dd-wrt worked regardless of the improper settings.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.