Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dual Wan, Portforward not working on OPT-Wan

    Scheduled Pinned Locked Moved Routing and Multi WAN
    31 Posts 5 Posters 17.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tec
      last edited by

      Hi I still have problems to get Dual Wan and Portforwarding on the Opt-Wan working.
      normal Wan- PPPoe
      Wan2 - Static IP behind a bridge-Modem
      Wan3 - Ip by DHCP
      First I did all the "Advanced Outbound Nats for the Connections" without having the Modem on Wan connected. See the Pictures for the information of outbound nat. Then I created the Portforwards from the Opt-Wan interfaces to the Clients. I rebooted to be sure and everything worked fine

      Now I connect the DSL Modem and try to establisch the normal Wan connection.
      1. I can go out via normal WAN only if the Connection is brougt up at boot time
      2. with the PPOE Connection the Portforwards from the OPT-Wans are not Workind anymore. It is very strange becaue you can see at the attached logged file the packets pass the Firewall but you cant establisch the RDP connection.
      3. Portforwards from WAN work without any Problem.

      I am running Rc3, which was installed from scratch. No additionals Services as TrafficShaper, Dyndyns or VPN is running.

      Does someone have a idea?
      Regards
      ![outbound Kopie.jpg](/public/imported_attachments/1/outbound Kopie.jpg)
      ![outbound Kopie.jpg_thumb](/public/imported_attachments/1/outbound Kopie.jpg_thumb)
      ![log Kopie.jpg](/public/imported_attachments/1/log Kopie.jpg)
      ![log Kopie.jpg_thumb](/public/imported_attachments/1/log Kopie.jpg_thumb)
      ![outbound Kopie.jpg_thumb](/public/imported_attachments/1/outbound Kopie.jpg_thumb)
      ![log Kopie.jpg_thumb](/public/imported_attachments/1/log Kopie.jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Show us the portforward at optwan and the firewallrule for that portforward please.

        1 Reply Last reply Reply Quote 0
        • T
          tec
          last edited by

          Okay here is the Porftforward and correspondig firewall rule. The firewall rule was created through the Nat-Rule, the checkbox automatically create firewallrules was ticked.

          portforward.jpg
          portforward.jpg_thumb
          rule.jpg
          rule.jpg_thumb
          portforward.jpg_thumb
          rule.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            Does it work if you disable the advanced outbound nat? I think some of these rules might mix things up. We do enable nat automatically if an interface has a gateway.

            1 Reply Last reply Reply Quote 0
            • T
              tec
              last edited by

              Yes I had it working wothout "Advanced Outbound Nat". The reason why I enabled this was that I wanted to put a Counter Strike Source Server on the Internet that needs this "Static Port Feauture". The weird things is that when the PPPOE device at WAN could not make an Internet connection, the Portforwards are working on the Opt-Wans.
              Do you have any suggestions ?

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                I think only one mapping can use a static sourceport at the same interface for the same port. You tried to assign several times the same sourceport at the same interface for traffic from different subnets. If the the pppoe WAN is down it bypasses one of these settings (the first match) and goes down to the OPTWAN static port rule which then works. I guess something like that is going on.

                1 Reply Last reply Reply Quote 0
                • T
                  tec
                  last edited by

                  Ok, I will trie to delete the "static mappings" the next time when I am in front of the router and post the results here.

                  1 Reply Last reply Reply Quote 0
                  • R
                    rob_v
                    last edited by

                    Hmmzz i got the same problems…
                    I installed PFsense again (clean install)
                    And only made 1 rule (RDP)
                    First i tryed it on WAN 1 this works
                    Then i tested on WAN 2 (OPT) and it doesn't work and i programmed the rules same.

                    I hope they will find a solution for this problem.

                    1 Reply Last reply Reply Quote 0
                    • H
                      hoba
                      last edited by

                      Upgrade to 1.0-RELEASE we fixed a condition where firewallrules were not applied before rebooting in certain circumstances.

                      1 Reply Last reply Reply Quote 0
                      • R
                        rob_v
                        last edited by

                        @hoba:

                        Upgrade to 1.0-RELEASE we fixed a condition where firewallrules were not applied before rebooting in certain circumstances.

                        I did that… But without any positive results...

                        1 Reply Last reply Reply Quote 0
                        • T
                          tec
                          last edited by

                          rob_v do you have a PPPOE connection on WAN?
                          I will try the next days to upgrade and solve the Problem

                          1 Reply Last reply Reply Quote 0
                          • R
                            rob_v
                            last edited by

                            I tested it with:

                            WAN 1 static

                            WAN 2 static

                            And with :

                            WAN 1 DHCP

                            WAN 2 static

                            Thx :)

                            1 Reply Last reply Reply Quote 0
                            • T
                              tec
                              last edited by

                              I am also now on Release 1:

                              • Portforwarding on Opt-Wan not working
                                -deleted my static port entries but not effect

                              Now backed up config XML
                              -deleted all advanced outbound rules and enabled ipsec passthrough, and deleted "oubound tags" in config.xml installed again Pfsense, restored config.xml, did the normal reboot and it doesn´t even work work without having toutbound Nat enabled :-(

                              Still the same, the Firewall Rule is showed as above in the firewall log page but nothing happens

                              Right now I have the feeling that Dual Wan and Portforwarding is a mess or I am to stupid for this and just how it seems the latter is more likely

                              1 Reply Last reply Reply Quote 0
                              • H
                                hoba
                                last edited by

                                I have several locations where I'm using portforwards on multiwan setups (at WAN and OPT-WAN) without any issues. You really seem to have something wrong. I suggest starting over and not reusing the old config.

                                1 Reply Last reply Reply Quote 0
                                • T
                                  tec
                                  last edited by

                                  Hoba, do you have on any location PPPOE as a Wan Interface?

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    hoba
                                    last edited by

                                    uhm, no. Static everywhere. Maybe that makes a difference. Can you send me /tmp/rules.debug and your config.xml to holger dot bauer at citec-ag dot de?

                                    Btw, how did you make PPPoE work at OPT-WAN  ???

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      tec
                                      last edited by

                                      Hi Hoba,
                                      there maybe some Kind of missunderstanding:
                                      Wan (the normal PFsensenstandartwan) = Pppoe
                                      Opt-Wan (Optional Interfaces with static ips or they get them per DHCP).

                                      Therefore I asked if in any of your Setups you have the normal WAN as a PPPoe Connection?

                                      1 Reply Last reply Reply Quote 0
                                      • H
                                        hoba
                                        last edited by

                                        PPPoE at WAN shouldn't affect portforwards at OPT-WAN.

                                        1 Reply Last reply Reply Quote 0
                                        • T
                                          tec
                                          last edited by

                                          Shouldn´t….
                                          I noticed only on an old install that when I plugged the cable of from the PPPOE Connection and rebooted the Portforwards where working on Opt-Wan this is the weird thing.

                                          On your Opt-Wans. Do they have all Ip from an ISP ? I have on my Opt-Wan a 192.168.0.0/24 Adress because I need that a DSL Modemroute makes the PPPOE connection or is this a Problem that I am using a private Ip range on the OPT_Wan Interface?
                                          Regards

                                          I will install the next day from Scratch and make Babysteps, maybe I ca find exactly out at which Point the Problem lies.

                                          Should I still mail you the requested files?

                                          1 Reply Last reply Reply Quote 0
                                          • J
                                            jeroen234
                                            last edited by

                                            did you uncheck this option on the opt interface ?

                                            Block private networks
                                            When set, this option blocks traffic from IP addresses that are reserved for private
                                            networks as per RFC 1918 (10/8, 172.16/12, 192.168/16) as well as loopback addresses
                                            (127/8). You should generally leave this option turned on, unless your WAN network
                                            lies in such a private address space, too.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.