Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Attempting to allow users behind my firewall out

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mpcs
      last edited by

      I'm having an issue allowing a user to ssh from behind the firewall out to a remote server… Can anyone give me pointers on what I need to do to make this work? I have attempted to allow pass rules to both the wan and the lan side but the user still has no luck..

      My setup is fairly standard. I have one nic (wan) with an external ip address, and another (nic) lan connected to the local network. Pf is offering dhcp, and nat service.

      Thanks for your time reading this!

      Regards,
      Mpcs

      1 Reply Last reply Reply Quote 0
      • M Offline
        mpcs
        last edited by

        Not sure if this makes a bit of difference but I do have the traffic shaper enabled…

        1 Reply Last reply Reply Quote 0
        • jahonixJ Offline
          jahonix
          last edited by

          The shaper shouldn't be the problem.

          Delete the ssh rule on WAN except you want to allow incoming ssh traffic ORIGINATING from the outside world.
          You need one rule on your LAN tab that allows the IP of that specific user to access from any port to ssh port on any machine. That should do.

          1 Reply Last reply Reply Quote 0
          • M Offline
            mpcs
            last edited by

            Alright… I've attached a file of the rule I added to the lan. I'm attempting to get both a playstation and a user with SSH access to what they need. Here is my attached rule for the playstation. I'm having no luck with it. Do I need to change something in the nat to make this work?

            1 Reply Last reply Reply Quote 0
            • jahonixJ Offline
              jahonix
              last edited by

              Well, actually you missed the attachment…

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.