Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I can not block WAN port?

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mucipM
      mucip @Gertjan
      last edited by mucip

      Dear @Gertjan ,
      Unfortunatelly I can not back to defaults. Because I have many things in config yes.
      But this is really very interesting.
      Where this 1024 port come from?...

      Regards,
      Mucip:)

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @mucip
        last edited by

        @mucip device in front of pfsense.. Your wan rules shown would not allow for any port forwards you have - even if you have cameras behind pfsense.

        Do you have rules in floating? So you have port forwards that send to your cameras, but for those to work your wan would have to allow for that.. Which you show there are not any - unless you have something floating.

        nor would your rules even allow for the default 80/443 that pfsense could be listening on.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        mucipM 1 Reply Last reply Reply Quote 0
        • mucipM
          mucip @johnpoz
          last edited by

          @johnpoz,
          No, I don't have any floating rules.

          a2b57bbc-f2a5-435c-8d4f-fcdd45a5871e-resim.png

          By the way I have NAT for camera and web server behind the pfsense. Everything normal. Except 1024?!

          Regards,
          Mucip:)

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @mucip
            last edited by johnpoz

            @mucip said in I can not block WAN port?:

            By the way I have NAT

            No you don't there is no way your port forward in pfsense would work without a firewall rule to allow it.f And you have no rules in floating and no rules on your wan that would allow it..

            So you could have whatever you want in port forwards, and they wouldn't work.

            I would suggest you look at your full ruleset, maybe your gui is not showing you the rules or something - but from what you posted you could have 100 different port forwards and none of them would work, because you have no firewall rules on the wan to allow them.

            https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            mucipM 1 Reply Last reply Reply Quote 0
            • mucipM
              mucip @johnpoz
              last edited by

              @johnpoz ,
              Maybe I misexplained sory.
              I have NAT rules and also releated Firewall rules. No problem. Cameras are working. 80/443 are working and other NAT ports are working correctly.
              Maybe there is 1024 port opne in rules but GUI don't show it I don't know?

              Can I see the firewall rules in console viewer to check?

              Regards,
              Mucip:)

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @mucip
                last edited by

                @mucip said in I can not block WAN port?:

                Maybe I misexplained sory.

                The wan rules you posted would not allow anything.. Did you not post up your firewall rules?

                These rules show nothing would be allowed

                rules.jpg

                And again - with what you posted there is zero reason to put in any blocks because every interface has a default deny.. And that rule you put in for 1024 would never trigger anyway because you have the source port set to 1024, not the destination port.. The traffic you show as open is TO 1024, not from a source port of 1024

                If you want people to help you - post up your full port forwarders and your full wan rule set.. But what you posted, no port forwards would be allowed.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                mucipM 1 Reply Last reply Reply Quote 0
                • mucipM
                  mucip @johnpoz
                  last edited by

                  @johnpoz ,
                  Sure I have many more rules after than last 1024 line above picture. I don't want to send them all rows because of security reasons.

                  Yes I changed it to destination port. But still looking open unfortunatelly?!

                  95bb7372-f58b-48c2-af57-2ffcca4d9f6e-resim.png

                  Regards,
                  Mucip:)

                  Bob.DigB johnpozJ 2 Replies Last reply Reply Quote 0
                  • Bob.DigB
                    Bob.Dig LAYER 8 @mucip
                    last edited by Bob.Dig

                    @mucip NAT rules can be set to "pass", so that is a possibility. But if you don't know the difference between source and destination port, you have bigger problems to begin with. 😉

                    mucipM 1 Reply Last reply Reply Quote 0
                    • mucipM
                      mucip @Bob.Dig
                      last edited by

                      @Bob-Dig,
                      No. There isn't any line ported 1024 in NAT page either.

                      Regards,
                      Mucip:)

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @mucip
                        last edited by johnpoz

                        @mucip because its not pfsense - do you have a port forward sending 1024 somewhere? If not then pfsense should not be listening on that port that is for sure.. But you can easy check with a netstat.. And again the rules you posted wouldn't allow anything.. can not help you figure out what you have that is allowing answer from some port if can not see your rules.

                        1024 can be used for modem admin, etc. it is quite possible your isp device in front of pfsense is answering on that..

                        Here is what I would do, do a simple sniff on pfsense wan - go to can you see me . org send some traffic to tcp 1024.. Do you see an answer.. If you do then pfsense or something behind it answered.. If you do not even see the 1024 hit you, then something upstream answered, or even if you do see it hit pfsense wan - if you don't see an answer then its not showing up because pfsense answered - but something in front of your pfsense did.

                        Here is example of sending traffic to my wan on 1024.

                        canyou.jpg

                        So clearly my pfsense or nothing behind it answered - so it shows closed. Do the same test - do you see it hitting your pfsense, do you see pfsense answer it?

                        edit: here is an example of seeing either pfsense or something you port forwarded to answering... See how I see a response sent back with my packet capture on pfsense wan

                        answer.jpg

                        Because I port forward that port to something behind pfsense.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        mucipM 1 Reply Last reply Reply Quote 0
                        • mucipM
                          mucip @johnpoz
                          last edited by

                          @johnpoz said in I can not block WAN port?:

                          1024 can be used for modem admin, etc. it is quite possible your isp device in front of pfsense is answering on that..

                          This might be the answer.
                          There is modem in front of the PfSense. I need to check it too...

                          95585282-6ea6-488f-948e-f0eb689e16e1-resim.png

                          Regards,
                          Mucip:)

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @mucip
                            last edited by johnpoz

                            @mucip so - for your own sanity, do the packet capture on pfsense wan when you do that test, do you see that 1024 hit pfsense wan, do you see a response.

                            If you don't then clearly you have a smoking gun that something in front of pfsense answered it.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            mucipM 1 Reply Last reply Reply Quote 0
                            • mucipM
                              mucip @johnpoz
                              last edited by

                              @johnpoz said in I can not block WAN port?:

                              so - for your own sanity, do the packet capture on pfsense wan when you do that test, do you see that 1024 hit pfsense wan, do you see a response.

                              You're right. :)
                              I did not try Packet Capure until now. I will googling and inform you.

                              But it'looks modem answerign it?

                              Regards,
                              Mucip:)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.