Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DIfference between NAT and Rules ! Am going Crazy

    Firewalling
    4
    14
    7.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      techtra
      last edited by

      Hello Guys I am a new PFsense User I love it very much but however It Seems like you have to setup a Firewall rule for each NAT rule you have ? I added a second extension to make it my Wifi Subnet. I can't get it to work.
      Thanks

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Please rephrase your question.
        First your talking about rules, then about about wifi.

        What is your setup? What are you trying to achieve in the end?

        Yes NAT has different rules than the firewall.
        They are actually two entirely different things.
        One changes in frames passing through the firewall the source/destination, and the other controls which frames are allowed.
        There is the checkbox: "autocreate firewall rule" when you create a new NAT rule.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • B
          Bern
          last edited by

          I'd agree with GruensFroeschli;

          Inbound NAT controls the "port forwarding"
          Inbound rules govern that use of the forwarded port.

          You can have NAT without a rule (eg. for a public HTML server in your DMZ)

          You can rules without NAT (eg. controlling where ping is allowed from).

          Typically you will combine the two.

          Note that the rules apply to the result of forwarding, so if you have a public ip address of "a.b.c.d" and rule that forwards incoming a.b.c.d:8080 to 192.168.1.2:80, your corresponding rule will apply to 192.168.1.2:80, not a.b.c.d:8080.

          I think once you've made the mental separation in your head, you'll see that this is the right way of doing it.

          As GruensFroeschli says, you can auto-create the rule when creating the NAT entry.

          1 Reply Last reply Reply Quote 0
          • T
            techtra
            last edited by

            ok My other question is how can I add a computer into a DMZ Zone ? Opening all ports for testing purposes. there is no such thing as all ports ! I see I have to open each individual ports.
            and My MSN Video capapbility can't seems to work this is why I wanted to try this DMZ Zone.

            thanks

            1 Reply Last reply Reply Quote 0
            • GruensFroeschliG
              GruensFroeschli
              last edited by

              Forget about terms like "DMZ-zone".
              pfSense is a real firewall and not a cheap soho router you can get off the shelf in the market at your corner.

              I assume you dont have multiple public IPs and thus cannot make us of 1:1 NAT.

              If you want to forward multiple ports you can:
              a: forward a range. Simply set the "External port range: from" and the "External port range: to"
              b: use aliases. You can insert in all fields with a red background the name of an alias you created. An alias can contain multiple single ports and ranges.

              We do what we must, because we can.

              Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

              1 Reply Last reply Reply Quote 0
              • E
                Eugene
                last edited by

                @GruensFroeschli:

                You can insert in all fields with a red background the name of an alias you created. An alias can contain multiple single ports and ranges.

                Forgive me my ignorance - how do I create alias for port range or multiple single ports???
                In Aliases I have only hosts/networks options (pfSense-1.2)
                Thanks.

                http://ru.doc.pfsense.org

                1 Reply Last reply Reply Quote 0
                • GruensFroeschliG
                  GruensFroeschli
                  last edited by

                  Is the note really that hard to find?

                  Enter as many ports as you wish. Port ranges can be expressed by seperating with a colon.

                  Just press the + button to add multiple single ports/ranges.

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • E
                    Eugene
                    last edited by

                    @GruensFroeschli:

                    Is the note really that hard to find?

                    Enter as many ports as you wish. Port ranges can be expressed by seperating with a colon.

                    Just press the + button to add multiple single ports/ranges.

                    Sorry again, but may be it would not be really hard to find if I new where to search.
                    I do not have these words neither in Firewall->Aliases->Add new nor in Friewall->Rules->Add new…
                    I understand that I look stupid but I was searching for this feature long time ago and could not find it. And I would be happy to use this functionality of pfSense. Please - where?

                    http://ru.doc.pfsense.org

                    1 Reply Last reply Reply Quote 0
                    • GruensFroeschliG
                      GruensFroeschli
                      last edited by

                      What version are you running?
                      Maybe it's time to update :D

                      It's under Firewall->Aliases->Add
                      See the attached screenshot :)

                      Screenshot.png
                      Screenshot.png_thumb

                      We do what we must, because we can.

                      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                      1 Reply Last reply Reply Quote 0
                      • E
                        Eugene
                        last edited by

                        Confirmed - I am stupid.
                        Thank you very much.

                        http://ru.doc.pfsense.org

                        1 Reply Last reply Reply Quote 0
                        • T
                          techtra
                          last edited by

                          ok Pf Sense Block Video Ability for my network. so I can Only forward the port to only 1 pc ? it's anoying because I have 3 different computers that I might want to chat and do Video conference with. Any Advice ?
                          Thanks

                          1 Reply Last reply Reply Quote 0
                          • GruensFroeschliG
                            GruensFroeschli
                            last edited by

                            If you think forwarding ports only to one pc is only a limitation of pfSense find me any NAT capable device that is capable for forwarding frames to multiple PCs.
                            And then i'd like to see the mess your network ends in :p

                            Your options are to enable upnp, or configure your clients with different ports.

                            We do what we must, because we can.

                            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                            1 Reply Last reply Reply Quote 0
                            • T
                              techtra
                              last edited by

                              ok thanks, I never said it's a PF sense Limitation. Can you guide me withthe UPNP a little bit ?
                              thanks

                              1 Reply Last reply Reply Quote 0
                              • GruensFroeschliG
                                GruensFroeschli
                                last edited by

                                Your software has to support upnp as well.
                                If it does:
                                Just enable it and you're good.

                                We do what we must, because we can.

                                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.