Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense 2.1 Release - NAT Reflection not working

    Scheduled Pinned Locked Moved NAT
    52 Posts 9 Posters 26.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      kejianshi
      last edited by

      Haha - Just giving you minor crap…

      I can see that happening.  Just yesterday I didn't think I could effectively run several websites off my one IP and kurianoftheborge (or something like that) set me straight.  (At least I think so - haven't tried it yet).

      1 Reply Last reply Reply Quote 0
      • S Offline
        Supermule Banned
        last edited by

        Why cant you do that? Its either controlled through pfsense or the webserver delivering the sites :)

        1 Reply Last reply Reply Quote 0
        • K Offline
          kejianshi
          last edited by

          I'm not a website admin guy so yeah - Lets just say its new info to me.  I've not ever had a need for a reverse proxy, but if I did, clearly that would save me some $$$.

          1 Reply Last reply Reply Quote 0
          • S Offline
            Supermule Banned
            last edited by

            Its only needed if you deliver sites to different servers. If you have only one webserver with multiple sites, its fine with one ext. ip.

            1 Reply Last reply Reply Quote 0
            • K Offline
              kejianshi
              last edited by

              Well - As of yesterday I understand it it fine, but the day before that I didn't know that a reverse proxy could work with HTTPS like that.  Every day its something new…

              1 Reply Last reply Reply Quote 0
              • K Offline
                keropiko
                last edited by

                Hi all,

                I would like to ask a question. When enabling the NAT Reflection mode for port forwards to NAT+proxy in pfsense 2.1 stable, does it break the ftp proxy helper? I am trying to login through ftp to a device (from outside my network) with passive mode, with only port 21 forwarded to the IP of the device on lan (outside port is 57483) , but i get error on passive mode on filezilla client, like the many errors i have found for the ftp problems in posts on this forum. The problem is that the nat helper does not automatically configure the range for passive transfers, so i should disable the helper and forward a range of ports, but i would prefer this done automatically.

                Thank you.

                1 Reply Last reply Reply Quote 0
                • 5 Offline
                  5m1l3
                  last edited by

                  Hi all! I have same trouble, but my lan gw is already none.
                  Simple config, i have two int WAN and LAN, pfsense is VM, 64bit.

                  NAT:
                  WAN TCP * * WAN address 15555 10.20.0.253 15555

                  Firewall:
                  IPv4 TCP * * 10.20.0.253 15555 * none   NAT

                  Portforward not working.

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    Marv21
                    last edited by

                    Same here. Nat refelction isnt working :/

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      meruem
                      last edited by

                      Having trouble. I'm at work and connecting to my home internal networking using SSH localforward-ing.

                      Failing Scenario: (Me at work computer) Chrome with Proxy SwitchySharp (SOCKS5 or localforward SQUID) -> trying to connect to a web interface (synology disk station) using public ip address and port -> fail/timeout.

                      Working Scenario: (Me at work computer) Chrome with Proxy SwitchySharp (SOCKS5 or localforward SQUID) -> trying to connect to a web interface (synology disk station) using private ip address of the synology disk station and port -> success.


                      Any ideas how to get this working?

                      1 Reply Last reply Reply Quote 0
                      • S Offline
                        Supermule Banned
                        last edited by

                        Is your Synology using port 5001 as of the webinterface? Normally not. Set it to HTTP instead of 5001 as the target port redirect.

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          tipiewot
                          last edited by

                          Hello everybody,

                          Thanks a lot for this post, it finally worked great for me too !!!  8)
                          Never have guessed it could deal with LAN gateway… Very good job !
                          Does anybody know where this behavior come from ? What's the link between LAN GW and NAT Reflection ?  :o
                          Thank you for your answer... and the fix !

                          Pierre

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.