Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port forwarding help

    NAT
    nat port forwarding
    2
    6
    548
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zer0vini
      last edited by zer0vini

      Hello guys! Newbie here.

      I managed to access pfSense's GUI via WAN address by a firewall rule, and now I'm trying to make a NAT port forwarding rule so I can remotely access a server connected to pfSense via LAN. My NAT rule configuration is:

      WAN interface
      TCP protocol
      Default Source
      Destination:

      • Any type
      • Destination port from 8800 to 8800
      • Redirect to 192.168.2.49
      • Redirect port to 8800

      Let it be known that I'm trying to access this server via Windows' remote desktop, hence why I'm not using HTTP/S ports.

      When I manage to access said IP with said port, I can't manage to have any access to my server, even though I've checked both NAT rule and firewall rule built after NAT was stablished, and I can't seem to find anything wrong with it. Can someone help me with this? Is there also a way I can keep my port forwarding as normal and keep accessing the GUI via WAN? I'm not an expert in network rules and services, so any advice is appreciated.

      Thanks!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @zer0vini
        last edited by

        @zer0vini said in Port forwarding help:

        Any type
        Destination port from 8800 to 8800
        Redirect to 192.168.2.49
        Redirect port to 8800

        Let it be known that I'm trying to access this server via Windows' remote desktop, hence why I'm not using HTTP/S ports.

        It doesn't matter, which port you are using at all. However, is the server even listening on port 8800?

        Maybe the access succeed if you state "WAN address" for the destination in the NAT rule.

        Is there also a way I can keep my port forwarding as normal and keep accessing the GUI via WAN?

        As long as you use different ports on WAN for both services, you can access them independently.

        However, it's basically a bad idea at all to expose either of these services to the internet!
        You should better run a VPN server and access them over a secure connection.

        Z 1 Reply Last reply Reply Quote 0
        • Z
          zer0vini @viragomann
          last edited by zer0vini

          @viragomann Thanks for the info! I think I was fooling myself with the idea of being able to access both GUI and the server with the same WAN address, but thankfully, I have a second WAN connection for load balancing and failover functions. I get the idea of using a VPN for security purposes, but for now, I'm using some dummy equipments to understand the concept a bit better before trying any DDNS/VPN alternatives.

          I'll try doing this same thing but with the second WAN connection and see if it works.

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @zer0vini
            last edited by

            @zer0vini
            You can access both services on a single WAN IP, but they have to use different ports.

            You didn't mention, which port is used for the web gui, so I don't know if it would work with your set up.

            Z 1 Reply Last reply Reply Quote 0
            • Z
              zer0vini @viragomann
              last edited by

              @viragomann I'm using "Any" as port config for accessing the GUI via WAN. Indeed, I need to state a specific port so I can access more than one interface via WAN. Thanks for reminding me of that!

              1 Reply Last reply Reply Quote 0
              • Z
                zer0vini
                last edited by zer0vini

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.