Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How can I find out why LAN device is accessible even though I have no WAN ports forwarded and UPnP is disabled?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 642 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      imthenachoman
      last edited by

      I am using https://www.goodsync.com/. It uses UPnP to let me browse my computer's contents from their website (while not on my LAN).

      The thing is, UPnP is disabled on my pfsense box. And yet I can still browse the files on my computer from the GS website while not on my LAN.

      I installed GS on two VMs (that are getting IPs from pfs) and was able to access their files from the GS website. Very odd.

      How can I track down what is going on?

      7689261c-2531-41fa-b0a6-9e4c09850543-image.png

      781ce4a2-e51e-4403-ad6b-fd3977e666c4-image.png

      74ffe5c0-4373-4062-b95b-a1e66fdda7ce-image.png

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @imthenachoman
        last edited by

        @imthenachoman If software is installed typically that would connect out to the service. No port forwarding needed. Same way many remote control programs work.

        You could check Diagnostics/States for connections to/from the computers.

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        I 1 Reply Last reply Reply Quote 1
        • I Offline
          imthenachoman @SteveITS
          last edited by

          @steveits I don't follow. Once the app is running on my computer, I have to go to the GS website to initiate a connection to my computer. Wouldn't that need to come through the WAN port?

          S GertjanG 2 Replies Last reply Reply Quote 0
          • S Offline
            SteveITS Rebel Alliance @imthenachoman
            last edited by

            @imthenachoman Not if the software connects out to the service to check. We have an agent on all our clients’ PCs and because it checks in every few seconds we have almost immediate access, without any ports forwarded to each PC.

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
            Upvote 👍 helpful posts!

            I 1 Reply Last reply Reply Quote 0
            • GertjanG Offline
              Gertjan @imthenachoman
              last edited by

              @imthenachoman said in How can I find out why LAN device is accessible even though I have no WAN ports forwarded and UPnP is disabled?:

              I don't follow. Once the app is running on my computer,

              Yes, you do.
              As you already used Teamviewer ones in your live, right ? It's the same concept : the teamviewer app has to be launched on the device on your LAN.
              When you give some one on the phone the ID and password, that person can 'from the other end' also using teamviewer can access your PC / desktop etc just fine.
              No NATtted ports or uPNPN needed.

              Because the PC on LAN opens a connection to a teamviewer server.
              These connections are data channels and are bi directional. Ones the connection is initiated from the PC LAN side, commands, traffic etc can go both sides.

              And even better : why do you see the Google page from the Google web server on your PC, your browser ?
              Because your browser opened up a channel (TCPO connection) to the Google web server, and asked it a question : "give me the / page".
              The web server answered by returning the page content.
              After it showed the page, the browser stops the connection.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • I Offline
                imthenachoman @SteveITS
                last edited by

                @steveits said in How can I find out why LAN device is accessible even though I have no WAN ports forwarded and UPnP is disabled?:

                @imthenachoman Not if the software connects out to the service to check. We have an agent on all our clients’ PCs and because it checks in every few seconds we have almost immediate access, without any ports forwarded to each PC.

                Ah. I see. Thank you!

                @gertjan said in How can I find out why LAN device is accessible even though I have no WAN ports forwarded and UPnP is disabled?:

                @imthenachoman said in How can I find out why LAN device is accessible even though I have no WAN ports forwarded and UPnP is disabled?:

                I don't follow. Once the app is running on my computer,

                Yes, you do.
                As you already used Teamviewer ones in your live, right ? It's the same concept : the teamviewer app has to be launched on the device on your LAN.
                When you give some one on the phone the ID and password, that person can 'from the other end' also using teamviewer can access your PC / desktop etc just fine.
                No NATtted ports or uPNPN needed.

                Because the PC on LAN opens a connection to a teamviewer server.
                These connections are data channels and are bi directional. Ones the connection is initiated from the PC LAN side, commands, traffic etc can go both sides.

                And even better : why do you see the Google page from the Google web server on your PC, your browser ?
                Because your browser opened up a channel (TCPO connection) to the Google web server, and asked it a question : "give me the / page".
                The web server answered by returning the page content.
                After it showed the page, the browser stops the connection.

                I get that now. I didn't realize this is how it might work. Thank you.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.