• NAT/Port forwarding doesn't appear to be working whilst HAProxy is

    7
    0 Votes
    7 Posts
    1k Views
    johnpozJ

    So you sniffed on the machine your sending too?

    which is actually the gateway for these servers

    Does it see the traffic and answer it? If it doesn't answer it but sends to wrong gateway?

    It NOT going to work if the gateway for the machines traffic being sent to is not the pfsense forwarding on the traffic..

    If you want actual support then
    https://www.netgate.com/support/contact-support.html

    Here is what I can tell you in the 10+ years I have been on this site and using pfsense port forwarding issues are always PEBKAC...

    BTW your haproxy is prob working because it does a source nat.. So traffic would be coming from pfsense IP, ie the whole proxy thing ;)

  • static IP address problem

    5
    0 Votes
    5 Posts
    669 Views
    M

    thank you but
    he system is currently in school. I can't try it right now. Need some help?

  • PFSense NAT 1:1 IPs over VPN

    2
    0 Votes
    2 Posts
    407 Views
    P

    I thought I'd try to RTFM on doing this via a tunnel interface rather than VTI as per https://www.netgate.com/docs/pfsense/vpn/ipsec/routing-internet-traffic-through-a-site-to-site-ipsec-vpn.html
    I had not realized you could pipe 0.0.0.0/0 through a VPN tunnel.

    This config works without any issue, and considering the warning on the site: "There are also known issues with NAT, notably that NAT to the interface address works but 1:1 NAT or NAT to an alternate address does not work." - I would assume that this is a VTI limitation. Still if anyone has any additional info on this it'd be interesting to know.

  • NAT External URL to local exchange server

    7
    0 Votes
    7 Posts
    775 Views
    S

    @xeon said in NAT External URL to local exchange server:

    When you say Proxy, is it a Web Application Proxy server?

    @bepo was describing how to use HAProxy.

  • Port forwarding - what am I doing wrong?

    12
    0 Votes
    12 Posts
    1k Views
    ColinJackC

    @johnpoz Thanks - sorted!

    I have a bunch of ports that are included as a single port alias and one rule is used to port forward ... and that bunch included 25.
    Removed port 25 and hey presto.

    @johnpoz letting me know where it was being bounced from helped. Thanks.

  • NAT Reflection / Custom DNS / Reverse Proxy Configuration.

    2
    0 Votes
    2 Posts
    507 Views
    K

    On a side note, should I have my home network name as a subdomain as my external name?
    i.e. internal.domain.co.uk, or should I keep it as
    similardomain.local

  • NAT 1:1 issues

    4
    0 Votes
    4 Posts
    515 Views
    4

    I have two inet connections, one is standard residential (WAN) and the other is 5ip business (NET2). If I set it up to use the 5ip as WAN then I can get the NAT to properly route thru selected external ip's. I did not test the connection out the res. as NET2 in this configuration assuming that I would have the same problems as above but it does seem that there is some sort of issue trying to NAT out an OPT type interface.
    Anyone?

  • Voip.ms Configuration question

    2
    0 Votes
    2 Posts
    471 Views
    ?

    Can't anyone help me ?
    I tried pretty much everything I could imagine..
    I've tried also with siproxd without success either.
    As soon as I remove my pfsense appliance and return to my previous router voip is working.
    I can see that sip is working (registration is ok in the Ata and it show inbound and outbound sip traffic) but for rtp, only outbound and 0 inbound traffic....

  • 0 Votes
    3 Posts
    2k Views
    K

    @KOM

    Thank you!!
    answered everything

    Kind Regards
    Kinch

  • Port Forward Issues with a custom ARK Server

    4
    0 Votes
    4 Posts
    2k Views
    KOMK

    Something is not quit right here. You said the symptom of the problem was that you could access your local game server on LAN, but your users on WAN could not. NAT reflection will not address that issue. I suspect that there was a problem with the NAT you created and you somehow fixed it but thought it had to do with NAT reflection.

  • Port Forward not working

    5
    0 Votes
    5 Posts
    882 Views
    GrimsonG

    @shetu said in Port Forward not working:

    Last question what is difference between DMZ and Super DMZ (netis router)? I put my pfsense mac address to Super DMZ, it was not working.

    Read the netis router manual, this has nothing to do with pfSense. And "Super DMZ" is not a common term in networking, but rather some manufacturer specific thing.

  • Mobile client IKEv2 vpn, access to remote network(IPSec)

    2
    0 Votes
    2 Posts
    339 Views
    NogBadTheBadN

    @marcus-horne said in Mobile client IKEv2 vpn, access to remote network(IPSec):

    But i have no

    https://www.netgate.com/docs/pfsense/vpn/ipsec/configuring-an-ipsec-remote-access-mobile-vpn-using-ikev2-with-eap-mschapv2.html

    Automatic outbound NAT should be fine.

    "To pass all traffic, including Internet traffic, across the VPN, set the Local Network to 0.0.0.0/0" << this routes all the client traffic over the VPN.

    If you want specific clients to receive a specific IP rather than an address out the range check this out:-

    https://forum.netgate.com/topic/115795/guide-ikev2-ipsec-per-user-firewall-rule-settings-with-freeradius

  • Issue with FTP Passive?

    5
    0 Votes
    5 Posts
    1k Views
    K

    Thanks i send you the upload

  • Outbound 1:1 NAT

    7
    0 Votes
    7 Posts
    841 Views
    J

    Correct, sorry. I actually did what you mentioned above and it did sync to the secondary. Thanks.

  • Windows server VM can't access internet through pfSense

    3
    0 Votes
    3 Posts
    830 Views
    A

    Did you check what your WAN IP is? By default LAN IP on pfSense is 192.168.1.1 but sometimes default IP-pool from ISP equipment is 192.168.1.0/24 and in this case you have to change LAN IP-subnet.
    Did you connect your server to LAN port or OPT?
    What are your Outbound NAT Rules and Firewall Rules for LAN/OPT?

  • One way VoIP behind pfSense

    1
    0 Votes
    1 Posts
    743 Views
    No one has replied
  • NAT VPN Ipsec Pfsense

    2
    0 Votes
    2 Posts
    405 Views
    jimpJ

    If you are already connected to a site that has that network, then the other side must do NAT, not you. There isn't a way for you to hide that conflict using a single firewall.

    There are some ugly ways around it, like setting up a second firewall to handle that one VPN and do NAT between your main firewall and that firewall, but it's not ideal.

    You could also renumber your LAN, but that would be significantly more work.

  • [SOLVED] Replacing ISP router whits pfSense

    2
    0 Votes
    2 Posts
    677 Views
    _neok_

    @_neok I decided to put a router to not touch so much my pfSense, since I have other links and that way I have the cleanest configuration.
    Greetings!

  • 0 Votes
    1 Posts
    267 Views
    No one has replied
  • Incoming nat not working on port 6060 to pfsense

    4
    0 Votes
    4 Posts
    516 Views
    jimpJ

    If you see a state, it has passed the firewall.

    Check your target box. It's either not on, or it's blocked there. Most likely not a pfSense issue.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.