Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue accessing GUI

    Scheduled Pinned Locked Moved General pfSense Questions
    17 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Beno44 @luckman212
      last edited by

      Thank you @luckman212

      I have a new VoIP provider and not having static port prevents the VoIP to work correctly. I read somewhere that this would fix the issue. Since having this rule phones are working perfectly fine, not so much the access for some reason. Any other suggestions?

      luckman212L 1 Reply Last reply Reply Quote 0
      • luckman212L
        luckman212 LAYER 8 @Beno44
        last edited by

        @beno44 Yes- make a separate VLAN for your phones (ideally) and/or make your NAT rules more explicit to target only the traffic that actually NEEDS to have a static source port. That's likely just udp/5060. Your VoIP provider should have some documentation on what ports they use.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Yes, that's good advice. I would put outbound NAT in hybrid mode and add a single rule that catches the VoIP traffic with static source ports only. That could be by an alias of the VoIP devices as source for example.

          Steve

          B 1 Reply Last reply Reply Quote 0
          • B
            Beno44 @stephenw10
            last edited by

            @stephenw10 Screen Shot 2022-05-19 at 11.23.55.png

            luckman212L 1 Reply Last reply Reply Quote 0
            • luckman212L
              luckman212 LAYER 8 @Beno44
              last edited by

              @beno44 that rule you made has a few problems that I can see:

              • it needs to be higher up, otherwise the rules above it will match first and it will have no effect
              • I doubt if you want the source port to be set to 5060. Source ports are usually randomized, the dport should be enough unless your VoIP provider has a very odd setup
              • source of "any" is probably wrong too. I would make it match the LAN subnet that your phones are sitting on
              B 1 Reply Last reply Reply Quote 1
              • B
                Beno44 @luckman212
                last edited by

                @beno44 There wasn't much right...Tks again so much ;o)

                Screen Shot 2022-05-19 at 11.44.48.png

                luckman212L 1 Reply Last reply Reply Quote 0
                • luckman212L
                  luckman212 LAYER 8 @Beno44
                  last edited by

                  @beno44 Looking much better!

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Yup, that should work.

                    Personally I would use hybrid mode and allow pfSense to manage all the other rules.
                    In full manual mode you need to add rules your self should you add another subnet anywhere and it's all too easy to forget that.

                    Steve

                    B 1 Reply Last reply Reply Quote 0
                    • B
                      Beno44 @stephenw10
                      last edited by

                      Hey, @stephenw10

                      Everything is now working fine, thank god for that.

                      Don't have any issue trying the hybrid outbound but not too sure how to go about it. When I select Hybrid the exact same rules as manual outbound are showing.

                      luckman212L johnpozJ 2 Replies Last reply Reply Quote 0
                      • luckman212L
                        luckman212 LAYER 8 @Beno44
                        last edited by luckman212

                        @beno44 That's normal. The nice thing with hybrid is, if you change your LAN from 192.168.65.0/24 to e.g. 172.18.30.0/24, the NAT rules will automatically update. In manual mode, you'd need to remember to change them yourself.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @Beno44
                          last edited by

                          @beno44 said in Issue accessing GUI:

                          When I select Hybrid the exact same rules as manual outbound are showing.

                          No not really, all the rules would be in 1 rule.. Not all those individual rules..

                          To be honest doing full manual would require some very specific needs.. That I am actually having a hard time coming up with ;)

                          Hybrid is almost always the best method.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            When you set outbound NAT mode to manual all the auto-added rules are created as manual rules to start with so you still have connectivity.
                            When you go to Hybrid mode those manual rules are not removed but the auto rules are also applied. You will see most are duplicated. You can remove all the manual rules except the VoIP rule you added as the auto rules now cover that.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.