Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense 2.1 NAT port forwarding not working

    Scheduled Pinned Locked Moved NAT
    8 Posts 5 Posters 27.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z Offline
      zirou
      last edited by

      Hi everyone,

      I've some trouble getting port forwarding work on my firewall.
      I'm using 2.1 beta because of my mainboard, 2.0.3 doesn't recognize my 2 Nic's but 2.1 does so I can't  test with 2.0.3.

      This is what I have in the NAT Port forward
      WAN TCP * 12345 LAN address 12345 192.168.1.105 12345 Vivotek

      And this in the rule
      IPv4 TCP * 12345 192.168.1.105 12345 * none   NAT Vivotek

      Can someone please tell what's wrong in my config?
      Internally I can connect to the device without any problem.
      It works when I replace my pfsense system with my Vigor router/firewall that has the same port forward rule.

      thank you in advance.

      PfSense 2.1 beta on Gigabyte GA-C847N, 2GB memory, 500GB Sata 7.2k
      HP Proliant N36L WHS2011
      Netgear ReadyNas Duo
      ION 330 Ubuntu 10.04

      1 Reply Last reply Reply Quote 0
      • G Offline
        gderf
        last edited by

        Specifying a Source Port in a NAT or Firewall Rule is almost always a mistake. Leave that set to * (Any).

        1 Reply Last reply Reply Quote 0
        • Z Offline
          zirou
          last edited by

          Hi gderf,

          I did this yesterday because it says 'should usually be 'any'' but it doesn't work.
          I changed it back to any now but still having the same problem, in the log I can see it is blocked it says
          "@3 block drop in log inet all label "Default deny rule IPv4"

          WAN TCP * * LAN address 12345 192.168.1.105 12345 Vivotek

          PfSense 2.1 beta on Gigabyte GA-C847N, 2GB memory, 500GB Sata 7.2k
          HP Proliant N36L WHS2011
          Netgear ReadyNas Duo
          ION 330 Ubuntu 10.04

          1 Reply Last reply Reply Quote 0
          • G Offline
            gderf
            last edited by

            Try setting the NAT like this:

            WAN TCP * * WAN address 12345 192.168.1.105 12345

            Try setting the Firewall Rule like this if not automatically added by the NAT:

            TCP * * 192.168.1.105 12345 * none

            1 Reply Last reply Reply Quote 0
            • Z Offline
              zirou
              last edited by

              That's the solution, thanks a lot!!! Changing Lan address to WAN address directly worked  ;)

              PfSense 2.1 beta on Gigabyte GA-C847N, 2GB memory, 500GB Sata 7.2k
              HP Proliant N36L WHS2011
              Netgear ReadyNas Duo
              ION 330 Ubuntu 10.04

              1 Reply Last reply Reply Quote 0
              • S Offline
                satishaiwale
                last edited by

                Hi Folks,

                I need help.

                I have PfSense 2.0.3.

                I'm Trying to configure Port Forwarding.

                Could you please share doc or url .

                Thanks,
                Satish

                1 Reply Last reply Reply Quote 0
                • pttP Offline
                  ptt Rebel Alliance
                  last edited by

                  https://doc.pfsense.org/index.php/How_can_I_forward_ports_with_pfSense%3F

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    Dantalus
                    last edited by

                    @gderf OMG thank you so much, I've been struggling with this for weeks trying to get this to work correctly !

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.