Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Proxmox Pfsense only 1 public IP

    Scheduled Pinned Locked Moved Virtualization
    22 Posts 2 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      Faker03
      last edited by

      Hello ,
      First my Steup:

      Proxmox on a Dedicated Server
      Pfsense in a VM on Proxmox

      IPtabels to route all traffic to Pfsense exept Port 22, 8806
      2022-10-20_17h17_07.png
      Bridge vmbr0 for Pfsense
      Bridge vmbr1 for all VM later
      f9b23564-480b-473b-9b5e-116e4a7dda09-image.png

      So good to start with my problem.

      When i create a new VM on Proxmox that wokrs they get a DHCP adress from the Pfsense and has Outgoing Traffic like Ping works. But when i want to host something on it like a minecraft server.
      I cant open the Port.
      I have everything tried:

      • Firewall Rules
      • Port Forwarding

      In every similar Descripion everything workes fine.
      I really do not have any Idea what could be wrong.

      Thanks in advance! :)

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        How are you testing?

        Do you see blocks in the firewall logs? Or states created in the state table (Diag > States)?

        What port forwards are you adding?

        Steve

        F 1 Reply Last reply Reply Quote 0
        • F
          Faker03 @stephenw10
          last edited by

          @stephenw10
          Hi Steve,
          i have on a Ubuntu Container a Minecraft Server.
          So i try to connect to them via Minecraft.
          2022-10-21_09h41_30.png
          These are my Forward Rules
          2022-10-21_09h36_45.png 2022-10-21_09h36_55.png
          In the logs i dont see something that would be blocked and also not in the states.

          Elias

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Those screenshots are both of the firewall rules. Can we see the port forward?

            Where are you testing it from? Where is the client?

            I would also start with something easier to test directly like SSH and make sure that works.

            Steve

            F 1 Reply Last reply Reply Quote 0
            • F
              Faker03 @stephenw10
              last edited by

              @stephenw10
              Sry my bad i hvae picked the Wrong Screenshot.

              e8b59ae0-bab8-4aa6-a7af-874497105773-image.png

              This is the Port Forwarding.
              I will test it now with SSH

              Elias

              1 Reply Last reply Reply Quote 0
              • F
                Faker03
                last edited by

                Also with SSH i get a refused connection.

                5fce0366-5076-4171-b54b-3cea0ab432c7-image.png

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Do you see any states created in pfSense on either of those ports?

                  The port forwards looks correct. It seem like that traffic never reaches the pfSense WAN.

                  Steve

                  F 1 Reply Last reply Reply Quote 0
                  • F
                    Faker03 @stephenw10
                    last edited by

                    @stephenw10
                    ba86e3b2-1a7f-462d-9abf-2040c6e68a5a-image.png

                    These states i see but there is nothing visibe that the Rejected or Something like that.

                    1 Reply Last reply Reply Quote 0
                    • F
                      Faker03
                      last edited by

                      It seems that it was this checkmark

                      93906697-690b-4349-b0ac-16299fa14848-image.png

                      Thanks for your help!
                      Elias

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        So 10.0.0.2 is the pfSense WAN IP and 10.0.0.1 is the Proxmox host? Or some other VM you are testing from?

                        We do see that one SIP packet from some external address. And pfSense has opened a state for it so its being passed. Your WAN firewall rules are currently wide open.

                        Make sure you are actively trying to open an SSH connection when you check the states.

                        Steve

                        F 1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          It was the checksum off-loading? You were using vtnet NICs in Proxmox?

                          F 1 Reply Last reply Reply Quote 0
                          • F
                            Faker03 @stephenw10
                            last edited by

                            @stephenw10
                            Yes 10.0.0.1 is the Proxmox and 10.0.0.2 is the Pfsense.
                            I´m looking while i try to connnect to SSH. There are no new entries.

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              But you are now able to connect to the Minecraft server with hardware checksum off loading disabled?

                              F 1 Reply Last reply Reply Quote 0
                              • F
                                Faker03 @stephenw10
                                last edited by

                                @stephenw10 It was working for 10 sec then the SSH refused again.
                                I think that i use vtnet on Nic but i dont know what this mean.

                                1 Reply Last reply Reply Quote 0
                                • F
                                  Faker03 @stephenw10
                                  last edited by

                                  @stephenw10 no at the moment it does not work.

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Ok, where are you testing from? What is the source address?

                                    The pfSense WAN is wide open so you should see states created for any traffic that hits it. It looks like your test traffic never makes it to pfSense so either Proxmox is not forwarding it or it never arrives at Proxmox.

                                    Steve

                                    F 1 Reply Last reply Reply Quote 0
                                    • F
                                      Faker03 @stephenw10
                                      last edited by

                                      @stephenw10
                                      I have on the LAN a DHCP configured with the IP net 192.168.1.1/24 so the Container in Proxmox getting an IP from that.
                                      I´ve checked the Ip adress with the NAT Rules.
                                      I also checked the status from the SSH Server

                                      So far as i know should be the rules forward all traffic to the pfsense.

                                      37baeefc-0548-419a-99f6-144660706ae3-image.png

                                      a80cd92a-0fb1-45d2-8acc-0217d8ac1e4e-image.png

                                      2022-10-21_15h08_49.png
                                      75e68e2b-499d-4108-9e4f-7fe06156a93d-image.png

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        It doesn't look like a problem with the container, the traffic is not reaching the pfSense WAN.

                                        How are you accessing the pfSense webgui? From the same place? What is that place? Something outside the Proxmox public IP?

                                        Steve

                                        F 1 Reply Last reply Reply Quote 0
                                        • stephenw10S stephenw10 moved this topic from General pfSense Questions on
                                        • F
                                          Faker03 @stephenw10
                                          last edited by

                                          @stephenw10
                                          I acces the Pfsense via SSh over the Proxmox.
                                          I map the Port to my Localhost
                                          So via localhost2022-10-21_15h41_54.png

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Ah, OK.

                                            You should be able to access it directly if Proxmox is correctly forwarding all traffic to the pfSense WAN. That should include port 443 to the pfSense webgui.

                                            F 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.