Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT question

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 4 Posters 555 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      SudsMaker 0 @Jarhead
      last edited by

      @jarhead Yeah, I can get to the site internally.

      14608d07-7bcd-402b-8bc7-6b10e2049daf-image.png
      d0393e2e-11e7-40c1-aa25-5f2e56482b40-image.png

      J 1 Reply Last reply Reply Quote 0
      • J Offline
        Jarhead @SudsMaker 0
        last edited by

        @sudsmaker-0 And did the rule get created correctly too?
        Firewall/Rules/WAN.

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          SudsMaker 0 @Jarhead
          last edited by

          @jarhead It does look like the firewall rules for WAN were properly created.

          J 1 Reply Last reply Reply Quote 0
          • S Offline
            SudsMaker 0 @Jarhead
            last edited by

            @jarhead I'm rather new to pfSense and don't really know what NAT reflection is or how to configure/check it.

            S S 2 Replies Last reply Reply Quote 0
            • S Offline
              SudsMaker 0 @SudsMaker 0
              last edited by

              @sudsmaker-0 Here is a very crude/elementary scenario
              5498bd1e-2b0f-4371-aabe-f5371f3ee839-image.png

              V S 2 Replies Last reply Reply Quote 0
              • V Offline
                viragomann @SudsMaker 0
                last edited by

                @sudsmaker-0 said in NAT question:

                Here is a very crude/elementary scenario

                Indeed, it is.

                If you want the guys here to help you, you have to answer their questions and provide some details.

                From where you can access the site, from where not?

                The server IP in this graphic differs from the redirect target in the NAT rule.

                You said, you can access it from internal. From where and how? By its IP or by the FQDN?

                Is pfSense the default gateway in all involved network segments?

                1 Reply Last reply Reply Quote 0
                • S Offline
                  SteveITS Rebel Alliance @SudsMaker 0
                  last edited by

                  @sudsmaker-0 NAT reflection allows accessing a WAN IP NAT port forward from LAN or other networks. It is set here on the NAT rule:
                  bc8a8204-ec71-456c-838f-68c7c7726085-image.png

                  https://docs.netgate.com/pfsense/en/latest/nat/reflection.html

                  In your image, 172.0 is a public subnet...looks like AT&T's. Is that written correctly? If it was a private subnet (in 172.16/12) you'd need to uncheck the option "Block private networks and loopback addresses" on your WAN interface.

                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                  Upvote 👍 helpful posts!

                  S 1 Reply Last reply Reply Quote 0
                  • J Offline
                    Jarhead @SudsMaker 0
                    last edited by

                    @sudsmaker-0 Did you try the Shields Up site?
                    Need to know if it's open or not.

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      SudsMaker 0 @SudsMaker 0
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        SudsMaker 0 @SteveITS
                        last edited by

                        @steveits This fixed the issue for me.
                        Thank you!
                        328e3f2e-11cc-496f-9bc7-47a0c2966c07-image.png

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.