• H.323 Video Conference Codec behind PFSense *Guide / Explanation*

    Pinned Locked
    3
    0 Votes
    3 Posts
    25k Views
    D

    Long story short, to use H.323 behind a pfsense firewall, one needs to enable static-port NAT.

    Unfortunately neither H.323 nor SIP were designed with NAT in mind, in which case one needs either an ALG (which btw is part of Linux's netfilter since many years, but apparently missing from baseline pf/FreeBSD) or a NAT device that won't rewrite ports (a solution that will work if you only have one such device).

    Edit: Note that SIP software has been improved in recent years, and most recent implementations can work through NAT without a need for ALG or static ports, but it's still something one has to keep in mind when troubleshooting SIP issues.

  • Port Forward Troubleshooting

    Pinned Locked
    1
    3 Votes
    1 Posts
    30k Views
    No one has replied
  • New port forwards not working

    9
    0 Votes
    9 Posts
    36 Views
    F

    @enthu19 thank you so much, that worked!

    I learnt something new :)

    Thank you again enthu19!!!

  • pfSense IPSec + Manual Outbound NAT - No Traffic via VIP

    1
    0 Votes
    1 Posts
    15 Views
    No one has replied
  • ZTE ZXHN F6600P as bridge

    1
    0 Votes
    1 Posts
    17 Views
    No one has replied
  • Firewall Aliases IP Addresses with Port Forwarding

    5
    0 Votes
    5 Posts
    95 Views
    S

    In the firewall rule I changed the source address to the name of the firewall alias.

    Do you mean the source of the NAT rule? If not, try that.

  • Multiple outgoing IP, NAT/Routing not 100% working

    1
    0 Votes
    1 Posts
    18 Views
    No one has replied
  • [Tutorial] How to Secure and Implement Internal IPv6 NAT66/NPt

    1
    1 Votes
    1 Posts
    59 Views
    No one has replied
  • [Tutorial] How to Secure and Imeplement Internal IPv6 NAT66/NPt

    2
    0 Votes
    2 Posts
    66 Views
    No one has replied
  • unable to get firewall to route traffic

    52
    0 Votes
    52 Posts
    2k Views
    Z

    @Bob-Dig
    if I use cloudflared docker container then I can get to the sites no issue so not sure why it isn't working normally okay thanks will poke around more

  • PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03

    12
    0 Votes
    12 Posts
    531 Views
    johnpozJ

    @Gertjan said in PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03:

    Anyway, very soon we can ditch IPv4 and Natting and things become easy for everybody

    Yeah soon ;) they have been saying that for 20+ years already.. Soon ;)

  • Port forwarding not working on fresh install of 2.8.0

    4
    0 Votes
    4 Posts
    262 Views
    SpunkThingS

    @SteveITS

    Yes, by "lockout" I mean exactly that. Couldn't access the web interface, connect through SSH or even ping the machine until packet filtering was manually disabled.

    At that time there weren't any firewall rules except for the anti-lockout rule which is present on the LAN interface by default if I remember correctly.

    It was only after everything finally worked as intended that I started creating my own firewall rules, and from then onwards everything's been working fine. :-)

    My best (and honestly a little uneducated...) guess would be that my self created interface mismatch prevented me from connecting to the pfSense machine.

    I suppose the lesson here is that taking shortcuts such as the one described here can't be relied on. No more trying to rename interfaces on pfSense / FreeBSD. 😬

    On the bright side, no interfaces have gone down since performing a fresh installation and I sure gave it something to chew on.
    That's with the default RealTek kernel driver, by the way, the same one that kept acting up in the past and which prompted me to try the alternative v1.98 driver.

    For lack of a logical explanation I suppose we can call that a lucky coincidence.

  • NAT public IP through multi way

    3
    0 Votes
    3 Posts
    359 Views
    L

    @viragomann thanks a lot. From lan to wan works right.
    I must test how it works for some internal exposed services.

  • No "ports" in Port Forwarding

    3
    0 Votes
    3 Posts
    317 Views
    U

    @SteveITS , Thank you! Small oversight between chair and keyboard. I see it now.

    -JB

  • FreePBX & pfsense

    3
    0 Votes
    3 Posts
    382 Views
    N

    @STEPHANK Freepbx runs fine behind pfsense in various setups and is rather straight forward to configure
    In general not much is needed and in most cases not even any port forwards too.

    Do describe your configuration and setup.

  • Outbound NAT over IPSEC tunnel not working

    7
    0 Votes
    7 Posts
    629 Views
    S

    @viragomann said in Outbound NAT over IPSEC tunnel not working:

    @shaunmccloud said in Outbound NAT over IPSEC tunnel not working:

    And the minute I add a P2 entry in my pfSense box for a remote network of 0.0.0.0/0, all network traffic but local dies.

    So I'd assume, that the traffic is routed over the VPN, but not out on WAN.

    But this is only the half of the battle. The traffic must be natted on the remote site

    If the Meraki doesn't masquerade your subnets there is no way to go out to the internet through it.

    I decided to cheat, and throw a virtual pfSense box in the data center to connect to. I'll see how that works tomorrow.

  • Simple port forward error default deny rule ipv4

    6
    0 Votes
    6 Posts
    568 Views
    johnpozJ

    @TheCalvinator glad to hear finally sorted. Thanks.

  • Local DMZ to filter traffic for game server.(Category may be wrong)

    1
    0 Votes
    1 Posts
    117 Views
    No one has replied
  • SNAT IPsec not work

    13
    0 Votes
    13 Posts
    1k Views
    A

    @viragomann

    Morning my friend, some news about topic?

  • Upnp issue

    6
    0 Votes
    6 Posts
    647 Views
    G

    @Yasir Yeah, well unfortunately that's the way it's implemented so unless you can push for and get an update/improvement of the implementation, a script is the only other solution.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.