Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 3 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Rebel Alliance @morgenstern
      last edited by

      @morgenstern If it's a consumer grade account I could definitely see them blocking server connections. If it's CGNAT (100.64.0.0/10 subnet) like Starlink uses for IPv4 then it isn't going to work for any inbound connection...try IPv6 if they provide that.

      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
      Upvote ๐Ÿ‘ helpful posts!

      morgensternM 1 Reply Last reply Reply Quote 0
      • morgensternM
        morgenstern
        last edited by

        87305fb8-ab5a-458b-b27d-f88ea3d7b449-image.png

        Deleted the NAT rule and just added this WAN rule instead but no joy

        1 Reply Last reply Reply Quote 0
        • morgensternM
          morgenstern @SteveITS
          last edited by

          @steveits said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

          @morgenstern If it's a consumer grade account I could definitely see them blocking server connections. If it's CGNAT (100.64.0.0/10 subnet) like Starlink uses for IPv4 then it isn't going to work for any inbound connection...try IPv6 if they provide that.

          I guess I may have to speak to them. How would I establish whether it's this CGNAT? Is it a common thing nowadays?

          V 1 Reply Last reply Reply Quote 0
          • morgensternM
            morgenstern
            last edited by

            It's a /29 network by the way

            1 Reply Last reply Reply Quote 0
            • V
              viragomann @morgenstern
              last edited by

              @morgenstern
              https://en.wikipedia.org/wiki/Carrier-grade_NAT

              https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses

              morgensternM 1 Reply Last reply Reply Quote 0
              • morgensternM
                morgenstern @viragomann
                last edited by

                @viragomann said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                @morgenstern
                https://en.wikipedia.org/wiki/Carrier-grade_NAT

                https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses

                Ah yeah, I see what you mean:

                In April 2012, IANA allocated the block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255, netmask 255.192.0.0) for use in carrier-grade NAT scenarios.

                The public IP I got isn't in that range.

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @morgenstern
                  last edited by viragomann

                  @morgenstern

                  In April 2012, IANA allocated the block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255, netmask 255.192.0.0) for use in carrier-grade NAT scenarios.

                  The public IP I got isn't in that range.

                  And also not a RFC 1918?

                  So check if the packets even arrive on your WAN. You can use Diagnostic > Packet Capture to investigate.

                  Do you have any other inbound connections?

                  morgensternM 1 Reply Last reply Reply Quote 0
                  • morgensternM
                    morgenstern @viragomann
                    last edited by

                    @viragomann said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                    RFC 1918

                    Nope. It's 188.x.x.x/29

                    1 Reply Last reply Reply Quote 0
                    • morgensternM
                      morgenstern
                      last edited by

                      Okay, I got it!

                      So my simplified rule was too complex! ๐Ÿ™„

                      The source has to be any port from the trusted IP list to HTTPS port on the destination wan IP!

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Rebel Alliance @morgenstern
                        last edited by

                        @morgenstern said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                        any

                        Ah yes the source port is normally random. Easy to read over in a screenshot.

                        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                        Upvote ๐Ÿ‘ helpful posts!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.