• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

New COD MWII Blocked By pfSense

Gaming
new call of duty mwii blocked by pfsense
5
64
12.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    EmJeezy
    last edited by EmJeezy Oct 31, 2022, 2:04 AM Oct 31, 2022, 1:55 AM

    Hello,

    I am trying to run the new COD MWII on PC through Steam and it's getting blocked by my Netgate SG1100. Stuck at 'Status: Logging Into Online Services'.

    login-to-view

    Tried following the port forward steps for Steam listed here but COD remains blocked/stuck at 'logging into online services'.
    It is kind of interesting they do not have the info for 'PC', perhaps because the game is so new but I would presume the Steam port forward settings should work?

    login-to-view

    In any case, I cannot get COD MWII unblocked for the life of me. Here are my current port forwards and associated rule configs ->

    login-to-view

    login-to-view

    As a test I popped on a wireless hotspot, completely bypassing my pfsense firewall and COD MWII loaded right in, no issues. I snagged a connection baseline while successfully connected to COD and the ports looked different than what is suggested by portforward.com ->

    login-to-view

    Regardless, I tried portforwarding with the information I found through a successful connection to the game but nope! No luck connecting to the new COD MWII (2022 version) through my pfsense firewall.

    Furthermore, I tried enabling UNP, outbound nat, updating to latest version of pfsense, enabling hybrid outbound nat, etc but hitting a wall. Anyone know what the heck may be going on?

    Any help is appreciated.

    Thank you.

    G 1 Reply Last reply Oct 31, 2022, 6:55 AM Reply Quote 0
    • G
      Gertjan @EmJeezy
      last edited by Oct 31, 2022, 6:55 AM

      @emjeezy said in New COD MWII Blocked By pfSense:

      Any help is appreciated.

      It's normal that 'some site' doesn't know everything about 'some program' :

      login-to-view

      Have a look at site of the authors of the game, Activation.
      They published this list :
      https://support.activision.com/articles/ports-used-for-call-of-duty-games

      login-to-view

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      J E 2 Replies Last reply Oct 31, 2022, 1:06 PM Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator @Gertjan
        last edited by johnpoz Oct 31, 2022, 1:08 PM Oct 31, 2022, 1:06 PM

        There is no freaking way you need to allow for unsolicited inbound traffic to login..

        To host a game maybe, to allow for feature X maybe. But to login - nope no way. What your issue is not sure, but I would bet like my left nut it has nothing to do with allowing for inbound unsolicited traffic.

        If that was the case - then nobody behind a cgnat would be able to play this game for example. In what world would that make sense that a maker of a game would cut off a large portion of their possible users? Lets not forget complexity of forwarding ports, or failure for UPnP to work behind say a double nat, or by default its quite often disabled..

        So in such a scenario that inbound traffic is needed to even login, a huge portion of the user base would be unable to get in..

        As a test I popped on a wireless hotspot

        And you think that hotspot allowed unsolicated inbound traffic?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        E 1 Reply Last reply Oct 31, 2022, 2:26 PM Reply Quote 1
        • E
          EmJeezy @Gertjan
          last edited by EmJeezy Oct 31, 2022, 2:26 PM Oct 31, 2022, 2:23 PM

          @gertjan Updated firewall rules and NAT to reflect the port forward info from activision but that did not help, same issue - stuck at 'status: logging into online services'.

          login-to-view

          login-to-view

          1 Reply Last reply Reply Quote 0
          • E
            EmJeezy @johnpoz
            last edited by Oct 31, 2022, 2:26 PM

            @johnpoz Disabled the LAN connection on my computer, used my wifi card to connect to my mobile hotspot and it works a 100%. Also works behind the firewall if I pop on my vpn (PIA).

            J 1 Reply Last reply Oct 31, 2022, 2:33 PM Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator @EmJeezy
              last edited by johnpoz Oct 31, 2022, 2:43 PM Oct 31, 2022, 2:33 PM

              @emjeezy none of which have anything to do with unsolicited inbound traffic. Your vpn sure isn't allowing inbound unsolicited.

              Forget your port forwarding for now, and troubleshoot why you can not connect, is something not resolving, are you sending traffic from your public IP an not getting an answer.

              When you use vpn, do you use different dns. Are you running anything pfsense like ips, or proxy, blocking dns with lists with pfblocker.

              Are you filtering outbound traffic? Or are you using the default any any rule?

              edit: Could be a peering issue with your isp. Since vpn and different connection (hot spot off your phone) would be taking a different route. But again neither of those connections would be allowing inbound traffic unsolicited to your IP

              Shoot it could be they have your isp Ips blocked.. But its not a inbound port issue. And out of the box pfsense doesn't block any outbound. So either you have modified that, are doing something with ips, or trying to proxy that is not working, or dns is a problem.

              I would think if there was something odd with this new game and even logging in with pfsense - then wouldn't the forum be on fire with people having issues, also on other social media. I can't believe your like the 1 user using pfsense wanting to play this new game ;) hehehe

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              E 1 Reply Last reply Oct 31, 2022, 3:45 PM Reply Quote 0
              • E
                EmJeezy @johnpoz
                last edited by Oct 31, 2022, 3:45 PM

                @johnpoz Good questions. Exploring your suggestions and will have a response soon. Thanks John, this has been a pain!

                J 1 Reply Last reply Oct 31, 2022, 3:59 PM Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator @EmJeezy
                  last edited by Oct 31, 2022, 3:59 PM

                  @emjeezy If your not doing anything with pfblocker or IPS, and are not running proxy. I would prob start with a packet capture, under diagnostics.

                  Filter it on your device that trying to login.. Set the limit to 0 so you not limited to 100 packets. Close down all other connections are your pc, don't have like 50 tabs open in your browser for example. Anything else that might be phoning home, or other apps running that make outbound connections. I would flush the local machines dns cache, ipconfig /flushdns on a windows machine. Open your browser (make sure its not using doh for dns).. Or run the application that lets you login. Launch the game..

                  Then try and connect.. Is any traffic actually blocked with logs? I wouldn't think so if your using the any any default rule. Let it try for a bit.. Then take a look at your packet capture. Do you see any dns that didn't get answered? Any connection attempts (syn) that didn't get back a syn,ack.

                  Any outbound UDP? that doesn't see to get a response.

                  Post up this pcap if you want others to take a look at what could be failing.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  R 1 Reply Last reply Oct 31, 2022, 4:49 PM Reply Quote 0
                  • R
                    rcoleman-netgate Netgate @johnpoz
                    last edited by Oct 31, 2022, 4:49 PM

                    @johnpoz I would also start from a clean firewall slate... no special rules, no ports forwarded, check your Outbound NAT to make sure it's clean, etc.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    J E 2 Replies Last reply Oct 31, 2022, 4:54 PM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @rcoleman-netgate
                      last edited by Oct 31, 2022, 4:54 PM

                      @rcoleman-netgate I would concur.. should be pretty much a default install..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      E 1 Reply Last reply Oct 31, 2022, 5:07 PM Reply Quote 0
                      • E
                        EmJeezy @johnpoz
                        last edited by EmJeezy Oct 31, 2022, 5:12 PM Oct 31, 2022, 5:07 PM

                        @johnpoz

                        When you use vpn, do you use different dns.
                        not explicitly no. On my hardline connection, my sg1100 provides DNS (using google 8.8.8.8)

                        Are you running anything pfsense like ips, or proxy, blocking dns with lists with pfblocker.
                        I do have pfblocker but it has been disabled for a long time. No other proxy or ips set up

                        Are you filtering outbound traffic? Or are you using the default any any rule?
                        firewall>nat>outbound setting, i am not filtering outbound. Only using default any any rule.

                        I would think if there was something odd with this new game and even logging in with pfsense - then wouldn't the forum be on fire with people having issues, also on other social media. I can't believe your like the 1 user using pfsense wanting to play this new game ;) hehehe

                        yah for sure. At first i thought it may be a network wide problem on activision end and in relation to the NEW COD MWII,but yah, quickly found I seem to be the only one having this odd issue ;-/

                        Ran a packet capture on my gaming pc LAN IP, while trying to connect to COD MWII ->

                        login-to-view

                        pcap is attached. packetcapture(1).pcap

                        J 1 Reply Last reply Oct 31, 2022, 5:08 PM Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator @EmJeezy
                          last edited by johnpoz Oct 31, 2022, 5:13 PM Oct 31, 2022, 5:08 PM

                          @emjeezy your pcap isn't actually attached, I can not download it.

                          You want to use the file upload, not image and might need to change to .pcap extension vs .cap

                          NTLM-wenchao.pcap

                          test cap

                          NTLM-wenchao.cap

                          Testing file upload of pcap or .cap they seem to be working.

                          Make sure you use file not image

                          login-to-view

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • E
                            EmJeezy @rcoleman-netgate
                            last edited by Oct 31, 2022, 5:12 PM

                            @rcoleman-netgate firewall is mostly default config, lightly configured. Will keep in mind though, ty.

                            J 1 Reply Last reply Oct 31, 2022, 5:15 PM Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator @EmJeezy
                              last edited by johnpoz Oct 31, 2022, 5:18 PM Oct 31, 2022, 5:15 PM

                              @emjeezy that capture shows no connections at all to anything external

                              login-to-view

                              And looks like you are limited to 100 packets.. But there is no info in that pcap that would help.. Since your not trying to go anywhere other than 172.16.25.2 which sure isn't a internet IP.

                              You have some remote desktop connection in that sniff - I see the RDP 3389

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              E 1 Reply Last reply Oct 31, 2022, 5:18 PM Reply Quote 0
                              • E
                                EmJeezy @johnpoz
                                last edited by Oct 31, 2022, 5:18 PM

                                @johnpoz i think the pcap i need to do is WAN and not local. Problem is with the WAN pcap i cannot filter (at least not from pfsense) on the local IP.

                                J 1 Reply Last reply Oct 31, 2022, 5:19 PM Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator @EmJeezy
                                  last edited by Oct 31, 2022, 5:19 PM

                                  @emjeezy no lan is fine.. That sniff has zero traffic going to any internet address in it.. To get to the internet you have to send it to pfsense right? But pfsense isn't seeing any traffic going to the internet in that sniff.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  E 1 Reply Last reply Oct 31, 2022, 5:20 PM Reply Quote 0
                                  • E
                                    EmJeezy @johnpoz
                                    last edited by Oct 31, 2022, 5:20 PM

                                    @johnpoz

                                    You have some remote desktop connection in that sniff - I see the RDP 3389
                                    yes i am remoted onto my gaming pc right now

                                    Trying the pcap again on lan..

                                    J 1 Reply Last reply Oct 31, 2022, 5:22 PM Reply Quote 0
                                    • J
                                      johnpoz LAYER 8 Global Moderator @EmJeezy
                                      last edited by johnpoz Oct 31, 2022, 5:23 PM Oct 31, 2022, 5:22 PM

                                      @emjeezy nor did see even any dns queries in that sniff. Only thing see in there is part of remote desktop connection.

                                      You most likely filled up your sniff before you even started anything because you didn't change the limit from 100 to 0

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      E 1 Reply Last reply Oct 31, 2022, 5:27 PM Reply Quote 0
                                      • E
                                        EmJeezy @johnpoz
                                        last edited by Oct 31, 2022, 5:27 PM

                                        @johnpoz said in New COD MWII Blocked By pfSense:

                                        You most likely filled up your sniff before you even started anything because you didn't change the limit from 100 to 0

                                        right, i forgot to change the 'count' to 0. changed it now and running another pcap while trying to connect to COD..

                                        J 1 Reply Last reply Oct 31, 2022, 5:28 PM Reply Quote 0
                                        • J
                                          johnpoz LAYER 8 Global Moderator @EmJeezy
                                          last edited by Oct 31, 2022, 5:28 PM

                                          @emjeezy make sure you flushed the clients local dns cache as well - so we can see if any dns queries it asks for are not being answered.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                          E 1 Reply Last reply Oct 31, 2022, 5:29 PM Reply Quote 0
                                          4 out of 64
                                          • First post
                                            4/64
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.