Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help nat/portforward

    Scheduled Pinned Locked Moved NAT
    12 Posts 3 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      Why do you have a double nat?  I would suggest remove that - can you not put your "modem/router" into bridge mode so that pfsense gets a public IP on its internet facing interface (wan)?

      If not then you have to forward the traffic you want to get to pfsense first on that "modem/router" to the pfsense wan IP, then on pfsense create your port forward to the inside box.  Or you need to put the pfsense wan IP into the dmz on your first nat device.

      Then just create a port forward on your pfsense.

      http://doc.pfsense.org/index.php/How_can_I_forward_ports_with_pfSense%3F

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • R
        robertog
        last edited by

        Hello John,
        thanks a lot for your reply, you are always ready to give me suggestions.
        So about your first question I cant setup modem/router in bridge mode

        Then I should do that:
        setup port forwarding in modem/router

        HTTP start port 80 end port 80 server ip address 192.168.0.2 (ip wan pfsense)

        setup in pfsense port forward

        if      proto    src. add    src.port      dest addr    dest port        nat ip                            nat port
        wan tcp/udp      *              *            wan net          80        192.168.1.* (device lan)      80

        so u think that is correct?
        I would appreciate sharing your ideas with me

        roberto

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well I highly doubt you need UDP on http.  And assume * is just place holder for the IP you want to send it too you can not send to wildcard.

          You might be better off putting pfsense IP in the dmz of your first nat router - or any future forwards you going to have to create in both places again.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • R
            robertog
            last edited by

            Hello John,
            so i assume my idea is ok, just i have to change tcp/udp in tcp on http sure. Yes i mean with * just any device in the lan.
            I dont know how i put pfsense ip in the dmz of nat router so I leave it configured how i explaned.
            Thanks!!!

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              What is the make and model of your modem/router ?  I would assume they support a dmz setup, if you give the make and model of it we can look to see.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • R
                robertog
                last edited by

                model is netgear dgn3500, I checked setup and default dmz server is 192.168.0.2 so shall i use this number for (pfsense)?

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  well if that is already set and that is your pfsense wan IP, you should be good to go and not need any forwards on your modem/router

                  edit: Some devices require being connected to specific lan port as well.

                  edit2:  I just looked at a manual for that model, and seems that dmz is disabled by default.  So make sure you enable it an you should be good for any future port forwards you need.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • R
                    robertog
                    last edited by

                    I followed your instruction and connection is ok.
                    So if now you think setup pfsense and modem/router is ok I will check portforwarding next days…
                    Thanks a lot!!!

                    1 Reply Last reply Reply Quote 0
                    • R
                      robertog
                      last edited by

                      hello,
                      just i did try from port forwarding tester but I continue to have problems.. Port 80 is closed.
                      Someone can help me?
                      thanks in advances.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        what is your wan rules, and what is your port forward rules?

                        If pfsense is in dmz of your router in front of pfsense, and didn't mess up the rules it should be working.

                        Now keep in mind many ISPs block port 80 inbound because your not suppose to run servers, etc.  Check with your ISP to see if they block specific inbound ports?

                        First check I would do is a sniff on pfsense wan interface - do you see the packets when you test?  I use canyouseeme.org

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • B
                          bardelot
                          last edited by

                          So about your first question I cant setup modem/router in bridge mode

                          Just trying to clarify: Are you using any features of the router except for the modem? Because the router supports disabling NAT under "Basic Settings"  (however this also resets the configuration to factory default).

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.