• RE: port forwards

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    R
    If the box MUST use a gateway ip of a device other than the pfsense box, go and redirect the traffic via another program to your machine.  Examples are as follows: If you have another Windows based computer there in your setup, and it uses the same gateway as your 192.168.20.2 computer (not the pfsense), install a port mapping program like PortMapper from AnalogX onto the computer.  It can be found at: http://www.analogx.com/contents/download/network/pmapper.htm Once installed, your must setup a port-forward rule on your pfsense to this 'temp' computer (say port 80), then setup PortMapper to forward port 80 over onto the 192.168.20.2 computer. I use this method all the time for when I need to access ports on computer not using pfsense as my main router as it uses another router/ISP to get out to the Internet. If you only have non-based Windows computers in your setup, I do think there are other redirect/port-mapping programs out there that can function the same as PortMapper. Good luck!
  • NAT to FTP long time

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    http://wiki.pfsense.com/wikka.php?wakka=FTPTroubleShooting
  • Specific NAT question.

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    Please do not cross post.  This was sent to the mailing list as well!
  • Help with natting – i think

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    What version?
  • Adv. Outbound NAT with Dual WAN (No Loadbalance) and Multiple VLAN?

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    T
    DNS is definitely the way to go, just get you name to resolve to WAN2 and then route the necessary port in.
  • Intranet can't connect smtp from Intranet

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    Hi akong, Have you the appropriate rules in place allowing your LAN (Client Workstation) to access your OPT interface (Mailserver)? Are you connecting via SMTP or POP or IMAP or RPC/HTTPS..? Dependant on the protocol being used, you would need to allow traffic to different ports on OPT1. If this makes sense? Cheers.
  • Nat issue with Opt1

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    3
    Thanks DotDash. The problem appears to have been that when I created my virtual ip's I used WAN instead of OPT1. It works great now. Thanks again for your quick response. Andy
  • Can't see my internal computers

    Locked
    30
    0 Votes
    30 Posts
    14k Views
    3
    I feel like a dunce.  I was away from my office and just got back. I looked at the postings and the last one triggered a new thought. I am trying to migrate from ipcop as well as moving from cbeyond. I looked at the ipchicken page and all of a sudden I realized that the default gateway for the internal box was still using the ipcop gateway. Once I changed the gateway from 10.0.1.2 to 10.0.1.3 (the new gateway) everything worked. I want to thank everyone who posted on this most profusely.  I feel like a huge weight has been lifted off of my shoulders. I wish I was a little more savvy about all the networking issues, but I guess trial by fire is the way I learn. Thanks again. Andy
  • Domain access issues with 1.2 Beta 1.

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    T
    Simple work-around.  Turn off DNS Forwarding.
  • Unable to forward SMTP to Exchange

    Locked
    11
    0 Votes
    11 Posts
    9k Views
    N
    Thanks for all the input. I have got it working now. I did as you suggested cmb and disabled the second NIC in the SBS 2003 box. All seems to be going well now. Thanks again. Nick
  • SIP/Voip - callers can hear me, but I can't hear them

    Locked
    12
    0 Votes
    12 Posts
    12k Views
    C
    It should work fine with 1.2b1 without any modification - as you see in your rules.debug output there, you have the NAT passthrough that's automatically generated. Definitely something out of your control and unrelated to pfsense.
  • NAT 1:1 newbie question

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J
    Thank you very much dotdash ! And by the way … PfSense is very nice. Switched from IpCop for it.
  • PPPoE (WAN) recconnects and AON + DynDNS

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    K
    I tried snapshot built at 2007-May-18 09:55:34 and the problem persists.
  • Problems portforwarding to 110

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Advanced Outbount NAT

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C
    1.2-BETA1 is available on the mirrors, there is an update available. Use firmware page to upgrade after you download the image.
  • Rule toggle

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    B
    Thanks Dot
  • 1:1 Nat / Multiple Public IP's

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A
    SOLVED, thanks.
  • S-NAT through VPN (IPsec)

    Locked
    12
    0 Votes
    12 Posts
    6k Views
    C
    @hoba: Not nasty at all Yeah, NAT is the nasty solution, it breaks all kinds of stuff you would typically want to use across a corporate WAN. Using unique subnets at each remote location is just good network design, it's how virtually every well designed multi-site corporate network works.
  • NAT - Webgui

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    L
    ok - my mom used to say (german speaking) "look first - then ask"… i just saw that the cvs already has this fixed... once again thanks a lot!
  • SIP hangs after a while

    Locked
    14
    0 Votes
    14 Posts
    9k Views
    M
    Try to decrease the register times to 60seconds. PFsense, along with some expesive-firewalls, have UDP timeouts of 30/60 seconds… after 60 seconds the incomming INVITE will be dropped. Using STUN doesnt solve the problem. stun is only used to let the phone know the public(masqueraded) address, and how it can open up UDP sessions. the public IP is needed because SIP (which is osi-layer7) does also contain the IP adress, and some SIP-devices will answer only on that and not on the layer3 ip...(workaround in asterisk is NAT=Yes) another good idea is to create a NAT rule which does static-port-mapping on the SIP & RTP sessions so that port 5060 stay's always 5060..... things i haven't checked yet for myself: SIP over TCP. TCP-sessions have much longer timeouts...but is rarely supported Conservative mode. good luck
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.