Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PortForward Not woking no matter what i do

    Scheduled Pinned Locked Moved Firewalling
    59 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @Dark_Prophet
      last edited by johnpoz

      @dark_prophet use the packet capture on pfsense.. Under diagnostic menu.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • D
        Dark_Prophet
        last edited by

        I did same test on LAN and has no output what so ever. can i see your rules on your port 2302 rule

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @Dark_Prophet
          last edited by johnpoz

          @dark_prophet I posted them...

          you sure that IP is correct.. if pfsense can not talk to that IP, then it can not send on the traffic - since it doesn't know the mac address of it.

          I posted the portforward and the rule that it generates on my wan..

          The rules on your wan are evaluated top down, if you have some rule that blocks before your allow then no it would never work, if you have some rule on floating that would block, again it wouldn't work.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • D
            Dark_Prophet
            last edited by

            ok i think you got it that could be the problem LAN interface is not getting anything

            i ping my Plex server on 32400 port on WAN and LAN and i get an output

            but now on 2302. what could be the issue now ? any ideas ?

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @Dark_Prophet
              last edited by johnpoz

              @dark_prophet have no idea you haven't posted your wan rules, nor if you have any rules in your floating. Nor again that pfsense can even talk to this IP you want to send 2302 too..

              Can pfsense ping this IP your trying to forward too, does it show mac address?

              pingarp.jpg

              If pfsense does not have the mac address of where to send traffic for this IP - then no it can not send it, even if your port forward and wan rules would allow it.

              You have different IPs in your plex forward vs this 2302 forward, one is to a .99 the other is to a .98 is that a typo? And your trying to send 2302 to your plex box as well?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • D
                Dark_Prophet
                last edited by

                Wan.png

                1 Reply Last reply Reply Quote 0
                • D
                  Dark_Prophet
                  last edited by

                  output.png

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @Dark_Prophet
                    last edited by

                    @dark_prophet what advanced thing did you do on that 2302 rule - see the gear on it.. Also I see no hits on that rule.. see the 0/0 B in the states - if you had sent traffic from the outside that rule matched on it would be something other than 0/0 like see your plex rule above it.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • D
                      Dark_Prophet
                      last edited by

                      LAn.png

                      there it shows MasterPC

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @Dark_Prophet
                        last edited by johnpoz

                        @dark_prophet all good info.. But what is that Gear Settings on that rule - means you did some sort of advanced filter on it.. Also it shows 0/0 hits on it - do you have something in floating rules that would prevent traffic from ever hitting the interface (wan) rule..

                        Also that shows its on a vlan, not your lan - if you sniffed on lan you wouldn't see traffic going to it..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • D
                          Dark_Prophet
                          last edited by Dark_Prophet

                          that's the sloppy state that i was trying to make it work lol
                          i did have something on flotting rules but i deleted everything and started from scratch

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @Dark_Prophet
                            last edited by

                            @dark_prophet

                            problem LAN interface is not getting anything

                            Did you do the packet capture on the correct interface - your lan would never see anything because from your arp table that IP is on your main_vlan interface.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • D
                              Dark_Prophet
                              last edited by

                              When i capture in MAIN_VLAN not output
                              when i capture on WAN i see traffic

                              my Plex server is on the same interface and i see output on all interfaces

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator @Dark_Prophet
                                last edited by

                                @dark_prophet well that doesn't make a lot of sense.. Are you showing that wan rule trigger when you send traffic - or is it still at 0/0

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • D
                                  Dark_Prophet
                                  last edited by

                                  thats why im scratching my head here lol
                                  still showing 0/0 on everything

                                  i wonder if the Main_vlan might be conflicting with something else.

                                  johnpozJ 1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @Dark_Prophet
                                    last edited by johnpoz

                                    @dark_prophet said in PortForward Not woking no matter what i do:

                                    i wonder if the Main_vlan might be conflicting with something else.

                                    No that has nothing to do with it... I just sent traffic to 2302 on your IP.. Does the rule show any evaluations?

                                    traffic.jpg

                                    Les see your port forward rules not the individual rules - all of them, want to see the order, did you place anything in the advanced source for that 2302 rule?

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      Dark_Prophet
                                      last edited by

                                      still nothing

                                      where did i forgot to cover my ip address lol 😬

                                      johnpozJ 1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator @Dark_Prophet
                                        last edited by johnpoz

                                        @dark_prophet you covered the last octet, but I got it from the ip you talked to the forum from.. As mod I can see that.

                                        I had to assume that was your IP, since the first 3 octets matched.

                                        So you still don't see any evaluations on that rule - shows 0/0 then yeah something is wrong.. You sure you have no rules in floating... You sure your rules reloaded after changing say floating - you say you removed stuff.. Do a reload of your filters..

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          Dark_Prophet
                                          last edited by

                                          lol forgot

                                          im taking all the pictures now

                                          johnpozJ 1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator @Dark_Prophet
                                            last edited by johnpoz

                                            @dark_prophet

                                            do a reload

                                            reload.jpg

                                            Did you copy and paste any rules - there was some issue going around where rules that were copied got the same ID..

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.