Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi-Wan Working, need help with port forwarding

    Routing and Multi WAN
    3
    10
    4.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alticon-brian
      last edited by

      Here is a diagram of my current network setup:

      In addition to that I have the following:

      Server @ 192.168.0.32

      Virtual IP (ProxyARP) for 66.92.160.12 on WAN Interface

      Outbound nat rule mapping 192.168.0.32 -> 66.92.160.12 on WAN:

      The following Port Forwarding Rule:

      And the following firewall rule:

      As of right now all traffic from 192.168.0.32 travels outbound on the proper IP.  The problem is that I can't pass any inbound traffic to the server.  I've flagged all incoming packets by that firewall rule to get caught by the local syslog but nothing shows up so i'm relatively certain it's a problem with the port forwarding.  Does anyone see any blatant problems with the setup?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        The outbound NAT rule order is wrong. Rules are applied top down. The last entry will never match which makes me wonder why the traffic should go out the correct VIP? However, the portforward will create it's own states for the connections that should not be affected by the outbound nat rule anyway. Only traffic originating from the server itself going out should be affected by the outbound rule.

        My guess is that the Virtual IP is not working correctly for some reason.

        1 Reply Last reply Reply Quote 0
        • D
          dia-andy
          last edited by

          Okay. My coworker and I have moved those rules around. When we do this, all outbound traffic is blocked from that specific machine.

          Also, what makes you think that the Virtual IP is not working and what can we do to fix it?

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            Can you show us the Virtual IP setup?

            1 Reply Last reply Reply Quote 0
            • D
              dia-andy
              last edited by

              Sure. Here it is.

              vip.png
              vip.png_thumb
              vip.png_thumb

              1 Reply Last reply Reply Quote 0
              • D
                dia-andy
                last edited by

                I should also note that I am trying to get traffic to come in on the 66.92.146.116 address on port 22/tcp

                1 Reply Last reply Reply Quote 0
                • H
                  hoba
                  last edited by

                  Try using CARP Virtual IPs. This should simply work.

                  1 Reply Last reply Reply Quote 0
                  • D
                    dia-andy
                    last edited by

                    Okay! Thanks! I'll that first thing Monday morning. Here's hoping…

                    1 Reply Last reply Reply Quote 0
                    • D
                      dia-andy
                      last edited by

                      Okay. So that seems to have worked, but only for traffic over port 80. I see a line in the firewall log which shows my external server hitting the machine behind the firewall and passing the traffic through to the internal address on port 80. When I try to hit that machine on port 21 or port 22, I see a block and the external IP address for the machine rather than the internal.

                      Why would it be passing traffic only on port 80? I've got the firewall rule set up to allow all traffic from anywhere to the internal address on any port.

                      The firewall log looks like this…

                      X  Jan 16 11:12:24 WAN2 204.2.XXX.XXX:38789 66.92.146.116:21 TCP

                      Jan 16 11:10:03 WAN2 204.2.XXX.XXX:38778 192.168.0.243:80 TCP

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        Search for ftp helper and portforwarding. This has been discusse a lot in detail. ftp is tricky.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.