Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense as proxy on wan

    2.1 Snapshot Feedback and Problems - RETIRED
    3
    10
    3.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xbipin
      last edited by

      is it possible to setup pfsense as a proxy on wan, meaning it gets packets from the wan then matches rules and sends those packets out of openvpn tunnels, in my country VoIP is blocked by isp but they allow VoIP within the country so i have setup a openvpn tunnel so all voip calls from lan go out of tunnel, i want to be able to use this tunnel from wan as well so when im in the country in a different location then i want to be able to use pfsense as the proxy which wouldnt take the packets then send it out of the openvpn tunnel

      1 Reply Last reply Reply Quote 0
      • T
        thermo
        last edited by

        • Crappy-salat allow voip in the country? really? They recently got some bluecoats and are interfering with Skype to Skype calls.
        • it should be possible with a firewall rule with an explicit gateway, in addition to a manual outbound NAT rule. Though I'm guessing as I haven't tried it.
        1 Reply Last reply Reply Quote 0
        • X
          xbipin
          last edited by

          yes, VoIP within country is allowed since long, many businesses use it also. they keep blocking VoIP in plain and encrypted form from within UAE to outside, Skype to Skype works fine but they got some new mechanism which detects Skype usage and blacklists ur ip after which all udp traffic is heavily filtered and i guess u might be suffering that, simply restart ur router to get a new ip and then blacklist is removed as long as u don't sue Skype.

          i have configured openvpn client and all my voip from within lan traffic goes out of it with manual nat enabled, now the tough part is to route traffic from wan to pfsense and then out of openvpn tunnel

          1 Reply Last reply Reply Quote 0
          • X
            xbipin
            last edited by

            any devs want to guide on this?

            1 Reply Last reply Reply Quote 0
            • E
              eri--
              last edited by

              It does not work with sipproxy?

              1 Reply Last reply Reply Quote 0
              • X
                xbipin
                last edited by

                actually i tried sipproxy for traffic from within lan but it has issues so my devices run direct with pfsense from within lan but the scenario is different in this case, we need to route traffic from the wan to pfsense then from there to openvpn client tunnel

                1 Reply Last reply Reply Quote 0
                • E
                  eri--
                  last edited by

                  For VoIP its a bit hard to do without a application proxy like sipproxy.
                  Though you can do a rdr(Port forward) for connections on wan to the sip tcp port and all udp incoming on WAN.

                  1 Reply Last reply Reply Quote 0
                  • X
                    xbipin
                    last edited by

                    create a port forward will create its associated firewall rule so basically what do i need to modify in that so all that incoming traffic can be routed out of the openvpn tunnel gateway?

                    1 Reply Last reply Reply Quote 0
                    • E
                      eri--
                      last edited by

                      You need to redirect to the openvpn sip provider normally.

                      1 Reply Last reply Reply Quote 0
                      • X
                        xbipin
                        last edited by

                        would it handle nat etc properly as i have advanced manual outbound nat enabled?

                        in port forward the destination ip i need to set as pfsense ip?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.