Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT question

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 4 Posters 555 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      SteveITS Rebel Alliance @SudsMaker 0
      last edited by

      @sudsmaker-0 If you are trying to connect to the WAN IP of pfSense from its LAN you need to enable NAT reflection on that NAT rule.

      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
      Upvote ๐Ÿ‘ helpful posts!

      1 Reply Last reply Reply Quote 0
      • S Offline
        SudsMaker 0 @Jarhead
        last edited by

        @jarhead Yeah, I can get to the site internally.

        14608d07-7bcd-402b-8bc7-6b10e2049daf-image.png
        d0393e2e-11e7-40c1-aa25-5f2e56482b40-image.png

        J 1 Reply Last reply Reply Quote 0
        • J Offline
          Jarhead @SudsMaker 0
          last edited by

          @sudsmaker-0 And did the rule get created correctly too?
          Firewall/Rules/WAN.

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            SudsMaker 0 @Jarhead
            last edited by

            @jarhead It does look like the firewall rules for WAN were properly created.

            J 1 Reply Last reply Reply Quote 0
            • S Offline
              SudsMaker 0 @Jarhead
              last edited by

              @jarhead I'm rather new to pfSense and don't really know what NAT reflection is or how to configure/check it.

              S S 2 Replies Last reply Reply Quote 0
              • S Offline
                SudsMaker 0 @SudsMaker 0
                last edited by

                @sudsmaker-0 Here is a very crude/elementary scenario
                5498bd1e-2b0f-4371-aabe-f5371f3ee839-image.png

                V S 2 Replies Last reply Reply Quote 0
                • V Offline
                  viragomann @SudsMaker 0
                  last edited by

                  @sudsmaker-0 said in NAT question:

                  Here is a very crude/elementary scenario

                  Indeed, it is.

                  If you want the guys here to help you, you have to answer their questions and provide some details.

                  From where you can access the site, from where not?

                  The server IP in this graphic differs from the redirect target in the NAT rule.

                  You said, you can access it from internal. From where and how? By its IP or by the FQDN?

                  Is pfSense the default gateway in all involved network segments?

                  1 Reply Last reply Reply Quote 0
                  • S Offline
                    SteveITS Rebel Alliance @SudsMaker 0
                    last edited by

                    @sudsmaker-0 NAT reflection allows accessing a WAN IP NAT port forward from LAN or other networks. It is set here on the NAT rule:
                    bc8a8204-ec71-456c-838f-68c7c7726085-image.png

                    https://docs.netgate.com/pfsense/en/latest/nat/reflection.html

                    In your image, 172.0 is a public subnet...looks like AT&T's. Is that written correctly? If it was a private subnet (in 172.16/12) you'd need to uncheck the option "Block private networks and loopback addresses" on your WAN interface.

                    Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                    Upvote ๐Ÿ‘ helpful posts!

                    S 1 Reply Last reply Reply Quote 0
                    • J Offline
                      Jarhead @SudsMaker 0
                      last edited by

                      @sudsmaker-0 Did you try the Shields Up site?
                      Need to know if it's open or not.

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        SudsMaker 0 @SudsMaker 0
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          SudsMaker 0 @SteveITS
                          last edited by

                          @steveits This fixed the issue for me.
                          Thank you!
                          328e3f2e-11cc-496f-9bc7-47a0c2966c07-image.png

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.