• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Unable to connect to OPT1 from LAN

Scheduled Pinned Locked Moved Firewalling
20 Posts 6 Posters 7.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    Perry
    last edited by Aug 8, 2011, 6:32 PM

    A local firewall on the file server with a wrong range?

    /Perry
    doc.pfsense.org

    1 Reply Last reply Reply Quote 0
    • B
      Bai Shen
      last edited by Aug 8, 2011, 6:35 PM

      @Perry:

      A local firewall on the file server with a wrong range?

      Tried turning it completely off and still couldn't connect.

      It looks like smb doesn't work well across subnets.  I'm okay with using FTP instead, but I'm not sure why FTP isn't working either.

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by Aug 8, 2011, 6:39 PM

        are you having active or passive ftp?

        Maybe you should try to create a rule in opt1
        allow smb traffic from servers to lan subnet

        1 Reply Last reply Reply Quote 0
        • B
          Bai Shen
          last edited by Aug 8, 2011, 6:58 PM

          @Metu69salemi:

          are you having active or passive ftp?

          Whatever Filezilla defaults to.  I didn't mess with any of the settings.

          Maybe you should try to create a rule in opt1
          allow smb traffic from servers to lan subnet

          How would that work?  What ports are you saying I should open?

          1 Reply Last reply Reply Quote 0
          • M
            Metu69salemi
            last edited by Aug 8, 2011, 8:07 PM

            Google has the answer. I almost had to find it twice
            few ports and remember to read that tcp/udp 445 also. it's not in the box

            1 Reply Last reply Reply Quote 0
            • B
              Bai Shen
              last edited by Aug 9, 2011, 1:25 AM

              @Metu69salemi:

              Google has the answer. I almost had to find it twice
              few ports and remember to read that tcp/udp 445 also. it's not in the box

              Since the LAN rule allows the traffic to OPT1, I'm assuming you mean I should open the port from the DMZ side.  Do I really need it if I only want access from the LAN to OPT1?

              I just tried opening 445 tcp/udp from the server to the LAN subnet and it doesn't seem to have had any effect.  I still can't connect a windows share.

              I ended up installing CopSSH, and that's working so far, but my transfer speeds are horrible.

              1 Reply Last reply Reply Quote 0
              • M
                Metu69salemi
                last edited by Aug 9, 2011, 3:48 AM

                SMB itself isn't the easiest traffic type to troubleshoot. Thats is the reason why to use opening ports from another interface also. and yes i do know what is the meaning of spi

                1 Reply Last reply Reply Quote 0
                • B
                  Bai Shen
                  last edited by Aug 9, 2011, 5:16 PM

                  @Metu69salemi:

                  SMB itself isn't the easiest traffic type to troubleshoot. Thats is the reason why to use opening ports from another interface also.

                  Well, like I said, I opened 445 tcp/udp from the server on OPT1 to LAN and I still can't connect from the LAN.

                  and yes i do know what is the meaning of spi

                  Huh?

                  1 Reply Last reply Reply Quote 0
                  • M
                    Metu69salemi
                    last edited by Aug 9, 2011, 7:48 PM

                    spi = Stateful firewall should keep ports open some while if connection is from inbound of it.

                    Then i have to admit, i don't have a glue what is the problem on this

                    1 Reply Last reply Reply Quote 0
                    • B
                      Bai Shen
                      last edited by Aug 10, 2011, 7:12 PM

                      @Metu69salemi:

                      spi = Stateful firewall should keep ports open some while if connection is from inbound of it.

                      Then i have to admit, i don't have a glue what is the problem on this

                      Me either.  We'll see how things go when I swap out my current box for the new one.

                      Honestly, it wouldn't be so bad if sftp wasn't so slow.

                      1 Reply Last reply Reply Quote 0
                      • P
                        pcbosrders
                        last edited by Aug 20, 2011, 3:20 AM

                        @Metu69salemi:

                        smb and ftp might need some more knowledge, try to use search. There is lot of discussion already in this forum

                        here is some info regarding SMB i'm in the proccess to allow file share between ubuntu and windows
                        through pfense
                        this might help on the ports to open

                        netbios- ns -137/tcp # NETBIOS Name Service
                        netbios- dgm -138/tcp # NETBIOS Datagram Service
                        netbios- ssn -139/tcp # NETBIOS Session Service
                        microsoft-ds -445/tcp #if you are using Active Directory

                        some other ports that might help
                        Ports 389/tcp For LDAP
                        port 445/tcp  NETBOIS was move to 445 after 2000 (CIFS)
                        port 901/tcp for SWAT service (web gui to configure Samba)

                        here is a link that i got most of the info i needed also there is a sample ip table
                        http://www.cyberciti.biz/tips/connecting-linux-unix-system-network-attached-storage-device.html
                        i know this doesn't have a sample for pfsense but you can get what rules to create from the ip tables

                        don't fix it, if ain't broken !!!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received