Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port Forward by Hostname

    Scheduled Pinned Locked Moved NAT
    13 Posts 2 Posters 7.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B Offline
      BBcan177 Moderator
      last edited by

      Can you post the settings you used for the NAT?

      Did you also use the "Filter Rule Association" setting to automatically create a Rule also? Or manually add a "Rule" to allow the NAT.

      This will output all of PFCTL's settings

      pfctl -sa

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • arrmoA Offline
        arrmo
        last edited by

        Hi,

        You bet - no problem at all. Attached shows the settings. And yes, I did allow automatic Filter Rule creation. I actually also enabled logging in that rule, but nothing seems to be showing up in the log … :(.

        Thanks!

        ![pfSense NAT.png](/public/imported_attachments/1/pfSense NAT.png)
        ![pfSense NAT.png_thumb](/public/imported_attachments/1/pfSense NAT.png_thumb)

        1 Reply Last reply Reply Quote 0
        • BBcan177B Offline
          BBcan177 Moderator
          last edited by

          Seems ok.

          Do you have any Rules above this one that might be passing that traffic? If there is a rule above this one, than the second rule won't see it.

          The Pic shows 192.168.2.23 buts its greyed out. Maybe just the way you created the PDF, but it should be Red/Maroon like you said earlier. The logs should show up in the "Firewall" logs.

          Are you able to access the WEB Server from the Internet?

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • arrmoA Offline
            arrmo
            last edited by

            Hi,

            The only rule above this one is "Block bogon networks" … actually, that's the only other Filter Rule, and no other Port Forwarding rules.

            Correct on the grayed out - I tried to generate a PDF, then to PNG ... lost the color in the process. And yes, it's the Firewall logs I'm checking - nothing there that I can see (no incoming traffic, only outgoing it seems).

            Nope, can't access the Web Server ... :(.

            Will keep digging, it could be me - that's a very real possibility .. ;).

            Thanks!

            1 Reply Last reply Reply Quote 0
            • BBcan177B Offline
              BBcan177 Moderator
              last edited by

              Make sure you don't have the "Block Bogons" on the LAN Side. That should only be set for the WAN.

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • arrmoA Offline
                arrmo
                last edited by

                Hi,

                I didn't create that one (seems to be auto-created), but I just checked … and you are correct, WAN only.

                Thanks!

                1 Reply Last reply Reply Quote 0
                • arrmoA Offline
                  arrmo
                  last edited by

                  OK, I may be on to something. If I manually go to WAN IP address (i.e. http://192.168.1.4/) … I get the pfSense login. So it seems that I can't port forward to a Web Server behind the pfSense box?

                  I just checked, and there is an "Anti-Lockout Rule" that seems to be auto-created, and it handles port 80? It also is forced to be first on the list. Trying to dig into it, to understand it.

                  Thanks!

                  1 Reply Last reply Reply Quote 0
                  • BBcan177B Offline
                    BBcan177 Moderator
                    last edited by

                    I haven't played with a WEB Server behind pfSense, but why don't you change the pfSense GUI to HTTPS and set a port like 443 or 8080

                    "Experience is something you don't get until just after you need it."

                    Website: http://pfBlockerNG.com
                    Twitter: @BBcan177  #pfBlockerNG
                    Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                    1 Reply Last reply Reply Quote 0
                    • arrmoA Offline
                      arrmo
                      last edited by

                      Hi,

                      Tried that … moved it to port 8080. It worked (getting there to 8080), but still can't forward 80 through ... :(. The other odd part is that this is on the LAN side (this rule) ... the Web GUI (for pfSense) shouldn't be accessible on the WAN side, should it?

                      Thanks!

                      1 Reply Last reply Reply Quote 0
                      • arrmoA Offline
                        arrmo
                        last edited by

                        Hi,

                        OK, just to close the loop .. updated to the latest version, and after reboot it started working.

                        Thanks so much for all the help!!!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.