Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Miniupnp full cone double NATincorrectly adding rules

    Scheduled Pinned Locked Moved NAT
    24 Posts 5 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      Nice!

      That change looks a lot cleaner than the config option as well.

      Hopefully they respond positively since it appears to follow their suggestions for where the change belongs.

      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      E 1 Reply Last reply Reply Quote 0
      • E encrypt1d referenced this topic on
      • S Saber referenced this topic on
      • E
        encrypt1d @jimp
        last edited by

        @jimp

        Looks like they committed a variation of my fix with slightly better error handling - but it is in!

        https://github.com/miniupnp/miniupnp/commit/c0d3a176509b7f659fa713c0d11597bdbfae7ca5

        So for all the double NAT folks out there, the fix is coming.

        How does the process unfold here, does it get updated in the pfSense repo?

        Bob.DigB jimpJ 2 Replies Last reply Reply Quote 3
        • Bob.DigB
          Bob.Dig LAYER 8 @encrypt1d
          last edited by

          @encrypt1d That would be fantastic, can't believe it.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate @encrypt1d
            last edited by

            @encrypt1d said in Miniupnp full cone double NATincorrectly adding rules:

            @jimp
            How does the process unfold here, does it get updated in the pfSense repo?

            Ideally, they'll put out a release, that release gets into the FreeBSD ports tree, and then we pull it in from there.

            In the past we have also set the port in our tree to build from a specific commit on their master branch if I'm remembering right, we did that not long after they put in the nat on rule support so we could start testing it.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            M 1 Reply Last reply Reply Quote 0
            • E encrypt1d referenced this topic on
            • E encrypt1d referenced this topic on
            • M
              mluna @jimp
              last edited by

              @jimp Hey, how are you?

              I couldn't see anything related in the new BETA release 22.05. Do you think this fix will make it to the final release?

              1 Reply Last reply Reply Quote 0
              • M
                Marc05
                last edited by

                It would be helpful to have this patch added in to help those with double NAT. It looks like last time it was updated on pfSense was ~4 years ago, and at this point it seems doubtful it's going to be updated any time soon.

                M 1 Reply Last reply Reply Quote 1
                • M
                  mluna @Marc05
                  last edited by

                  @marc05 said in Miniupnp full cone double NATincorrectly adding rules:

                  It would be helpful to have this patch added in to help those with double NAT. It looks like last time it was updated on pfSense was ~4 years ago, and at this point it seems doubtful it's going to be updated any time soon.

                  Yeah, I wish someone uploaded a patch at least as I myself am unable to compile the fixed app.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    The miniupnp project hasn't yet put out a release which includes that patch. We try not to incur technical debt or risk by adding in patches between releases when we can avoid it. Once they put out a new release we can update ours to use it.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    M 1 Reply Last reply Reply Quote 1
                    • M
                      mluna @jimp
                      last edited by

                      @jimp totally makes sense. Thank you!

                      1 Reply Last reply Reply Quote 0
                      • M
                        Marc05
                        last edited by

                        It has been broken for many years now, so another couple of years doesn't sound too terrible in that perspective. Still, it sucks :(

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.