• Internal clients accessing virtual IP

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    T
    Thanks Hoba, I enabled "NAT Reflection" then added the Port forwarding as you said and it just works!!! Then I think I don't need my old firewall box again. Thanks again to all psSense team.  Let me know if there's anything you think I can help. Tony.
  • 0 Votes
    6 Posts
    3k Views
    H
    TCP/UDP shouldn't cause a problem in your example as both should be open and be forwarded. Just note, that once you have autgenerated the firewallrule by adding the portforward the both rules (nat and firewall) are not linked together anymore. If you change one you have to change the other as well. Maybe this is/was the problem as you changed rules manually later?
  • 1:1 NAT + Alias

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    H
    If you want to have these changes backed up in your config run them by using hidden config.xml commands (see http://faq.pfsense.org/index.php?action=artikel&cat=10&id=38&artlang=en ).
  • NAT - Source Port - Range

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H
    That is correct behaviour. You can shift ports with it but not redirect a range of ports to the same port.
  • Multiply Public IPs

    Locked
    19
    0 Votes
    19 Posts
    7k Views
    H
    With the current implementation of loadbalancing probably not but I might be wrong. Who knows  ;)
  • Port forwarding *more nub help*

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    B
    aaa ok thank you that was simple. I was in the wrong area. Again you came trhough with some good info.
  • MOVED: Some gaming and pfsense battle.net/starcraft

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Port Forward to Virtual IP - local access problem

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K
    That solved the problem. Thank you! Regards, Krzysztof
  • Multiple IP - basic questions

    Locked
    6
    0 Votes
    6 Posts
    30k Views
    H
    Can you give us some details about your WAN setup and all WAN public IPs that you have (real interface IP and virtual IPs, type of WAN conection)? For the different virual IP types: CARP Can be used by the firewall itself to run services or be forwarded Generates Layer2 traffic for the VIP Can be used fo clustering (master firewall and standby failover firewall) The VIP has to be in the same subnet like the real interfaces IP ProxyARP Can not be used by the firewal itself but can be forwarded Generates Layer2 traffic for the VIP The VIP can be in a different subnet than the real interfaces IP Other Can be used if the Provider routes your VIP to you anyway without needing Layer2 messages Can not be used by the firewall itself but can be forwarded The VIP can be in a different subnet than the real interfaces IP Hope that helps a bit. Other
  • Prevent NAT from translating ports

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    Search the forum for "static port". You have to add an outbound nat rule for this and enable advanced outbound nat at firewall>nat, outbound.
  • How to automatically use SOCKS4 proxy for ftp connections

    Locked
    1
    0 Votes
    1 Posts
    9k Views
    No one has replied
  • Setup for NAT plus multiple public IP's

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    P
    http://www.firewall.cx/vlans-links.php for some vlan info as hoba said. I've just placed a ordered for a http://www.hp.com/rnd/products/switches/ProCurve_Switch_1800_Series/overview.htm or if all the pc are located in the same room go with more lan nic's to save some money. a diagram would be useful –-wan-----pfsense or use http://www.gliffy.com
  • Ftp problem?

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    U
    thanks.  congrats! after 1.0.1-SNAPSHOT-03-08-2007 snapshot update problem resolved. (but, i think nat reflection problem exist, may be) previous connection setup: lan to dmz connections used nat real ip (real wan ip) currently internal ip (opt ip) example: previous setup:  (my ordinary setup) nat reflection enabled nat: 212.x.y.93 -> 10.6.1.93 = port: 21 (used auto created rules) lan clients connection 212.x.y.93 success, but 10.6.1.93 not succes (wan to ftp server connection success) current setup: nat reflection enabled nat: exactly lan clients connection 10.6.1.93 success, but 212.x.y.93 not success (wan to ftp server connection success) if true, this is my new ordinary setup..
  • Help with SPA-3000 VoIP Box?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    PF (the filter used by pfSense) scrambles ports for advanced security by default. Some VOIP-Providers don't like that. Have a look at the following links how to shut down this behaviour for your VOIP-Phone: http://forum.pfsense.org/index.php/topic,104.msg5876.html#msg5876 http://forum.pfsense.org/index.php/topic,1047.msg12752.html#msg12752 There are other threads covering this too. Search for "static port" if you still have questions.
  • MOVED: Port forward for torrents not working on dual wan setup

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Help on port forwarding, please (deperately need help)

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    H
    Glad you got it working finally  :)
  • Port Forwarding with a Modem DHCP Always On

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H
    Try unchecking "block private IPs" at interfaces>wan.
  • NAT from WAN into LAN Possible ???

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    H
    You only create the portforward at wan so lan will be untouched. However if you want to make the webgui available at wan later you probably should use another port for it (and of course use https for it).
  • Port Forwarding Please?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Simple hardware not getting response when using UDP

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    H
    Scrambling ports is done as an extra security mechanism.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.