Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot open for after using secure SSL

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 4 Posters 1.6k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      ipcam.starinc
      last edited by ipcam.starinc

      Hi, after i use dyno and let's encrypt for my SSL, i try to add new ports to open but when i check using port checker all the new ports cannot be open, but all the old ports is still open,

      i try to use the old port and change the IP, then i access the website on public, but when i try to add new ports. it was closed.

      sample:
      port 83 is old port (before i use secure SSL)
      port 8013 is new port ( after i use secure SSL )

      did anyone experience this problem ?

      thank you.

      43c9f106-bfc8-46cc-8211-add22e9445dc-image.png

      75cc93a4-4825-4e0b-8856-92695da59d20-image.png

      a74d965d-358c-48c7-9e47-e9bc2d6cdec0-image.png

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @ipcam.starinc
        last edited by

        @ipcam.starinc well that checker does is send a syn.. If it gets no syn,ack back then yeah it would fail. So 192.168.2.177 isn't listening on port 8013 or it has a firewall not allowing traffic too that port.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        I 1 Reply Last reply Reply Quote 0
        • I Offline
          ipcam.starinc @johnpoz
          last edited by

          @johnpoz i can access it on local network. 8013
          88d06c5f-1bef-4d7a-a73d-a8db80754301-image.png

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @ipcam.starinc
            last edited by

            @ipcam.starinc said in Cannot open for after using secure SSL:

            i can access it on local network

            This mans your pfSense LAN interface allow TCP traffic to port 8013.

            When you are using the "port checker" (some web site ?), the traffic will not use the LAN interface. It will use the WAN interface.

            So the question is : does your pfSense WAN interface allow "TCP to port 8013" traffic ?

            This :

            60183da9-42da-4922-8461-ba5c85929620-image.png

            shows the NAT rule. Each NAT rule has an associated firewall rule. You will find them on the WAN interface. These firewal rules have matching packet counters ( !!) in front them.
            If these counters start to raise, you know they were 'used' (== matched) and traffic entered the WAN interface using that rule.

            So : what do these counters show you ?
            Does your TCP port 8013 traffic even reached pfSense ?

            Example : some of my WAN NAT Firewall rules :

            0d805de8-336a-4a17-bfd2-577b1ff77fb5-image.png

            The first shows the good old IPv4 : 11+ Mbytes of traffic.
            The second shows the incoming IPv6 traffic for the same device : 7+ GBytes of traffic.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Perhaps more accurately it means the server at 192.168.2.177 allows connections to port 8013 from local hosts but it might still be blocking external hosts. Either way it looks like a firewall issue on the server directly to me.

              But to be sure try checking the state table (Diag > States) in pfSense when you run the external port checker. Do you see it open states for port 8013 on both interfaces?

              1 Reply Last reply Reply Quote 0
              • I Offline
                ipcam.starinc
                last edited by

                thank you for the help guys. i fix the problem. i use 443 and HAproxy.

                thank you

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator @ipcam.starinc
                  last edited by

                  @ipcam.starinc not really a "fix" if you have device X on your network listening on port X, you can forward that port.. If its not working port X is not getting to pfsense wan, internet block, or incorrect setup on pfsense firewall to allow it.

                  Or your device X is not actually listening on port X, or it has a firewall blocking traffic to X from the source IP.

                  etc.. etc.. The "fix" if you want to forward that port is to actually fix what is stopping that from working. What your doing is working around your actual issue. Which is fine, but would still be good to know what the actual problem was - if port X is blocked to pfsense, using port Y that is not blocked works but I really wouldn't call it a fix ;)

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.