Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.0-RC NAT Port Forward LAGG interfaces.

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    5 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mmiller
      last edited by

      This is my problem at hand.  I'm trying to forward FTP and HTTP to a machine behind my firewall.  I've setup the NAT port-forward rules using linked rules.  When ever I try to hit FTP or HTTP I see the connection in the log being denied. When I hit the red button with a white X.  I see the following message on the denyed connection.

      The rule that triggered this action is:

      @1 scrub in on lagg0 all fragment reassemble
      @1 block drop in log all label "Default deny rule"

      I'm going to attach a png with my rules for the FTP port forward.
      autogenrules.png
      autogenrules.png_thumb

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by

        Can you please show us the firewall rules on top of you NAT firewall rule ?
        Firewall rules are working from top to down. Perhaps there is a rule before this rule which blocks ftp transfer.

        1 Reply Last reply Reply Quote 0
        • M
          mmiller
          last edited by

          If that was the case it wouldn't say that is was getting dropped by the default rule.  When I look at pfctl -s nat I don't see any rules or even if I do a pfctl -sr that show rules allowing traffic to 10.50.1.20.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            Guessing you're on a snapshot where check_reload_status isn't working right (some day(s) last week), upgrade to the latest if that's the case.

            1 Reply Last reply Reply Quote 0
            • M
              mmiller
              last edited by

              I'll give that a try.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.