Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to open port 110 or 25 (did with another port)

    Scheduled Pinned Locked Moved Firewalling
    26 Posts 6 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 2 Offline
      2chemlud Banned
      last edited by

      Hi!

      The first LAN Firewall rule allows EACH AND EVERYTHING, so no matter what you allow/prohibit thereafter: ALL traffic is already passed, nothing (IPv4) will care for what is in your table after line 1… simple as that ;-)

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Be specific.  Start with one thing.  Exactly what port do you want open from what sources to what destination.

        I think I already said this but be specific.  Include all details, but keep it to ONE item.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M Offline
          madmontero
          last edited by

          Thanks guys (both of you) for the info. I uncheck the "Default allow LAN to any rule " to anyrule (that really kills things…  made a webspecific rule to browse and then a port 110 to check and it's still blocked!

          I then reset it all (deleted my junk-only my port 55039 which works!) and pushed "Default allow LAN to any rule " to the BOTTOM.

          Made a PORT 110 NAT RULE and WAN/LAN RULE by copying the 55039 setup... nothing.

          common webscanners show everything is blocked.

          How come I was able to unblock this 1st port but nothing there after? Should I fire up another VM and test? possible corrupted install?

          port-scan.PNG
          port-scan.PNG_thumb
          port-scan1.PNG
          port-scan1.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            WTH are you doing there with the LAN port forwards???

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              Fine.  Don't listen.  Good luck.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • H Offline
                hda
                last edited by

                @madmontero:

                …
                Now I can't seem (for the life of me) to get port 25 or 110 to open up for Outlook/pop3/smtp stuff.
                ...

                Do you have a server listening (in) on port 25 OR does your client need to speak (out) to a port 25 ?

                1 Reply Last reply Reply Quote 0
                • M Offline
                  madmontero
                  last edited by

                  @hda:

                  @madmontero:

                  …
                  Now I can't seem (for the life of me) to get port 25 or 110 to open up for Outlook/pop3/smtp stuff.
                  ...

                  Do you have a server listening (in) on port 25 OR does your client need to speak (out) to a port 25 ?

                  A few Outlook clients that need to talk to POP/SMTP.

                  Incoming mail server pop.secureserver.net
                  Outgoing mail server (SMTP) smtpout.secureserver.net

                  These are blocked now..

                  DOK.. This is what installed by default, isn't this outgoing rule? LAN to WAN? pass all ports?

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    doktornotor Banned
                    last edited by

                    Dude. Put the default LAN rule back, delete the crap you created and be done. Dunno really what you are forwarding where when you are not hosting the mailserver.

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      madmontero
                      last edited by

                      The default LAN rule is in place! if I take out out my 55039 rule… then it stops being opened up??

                      Then what?

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        doktornotor Banned
                        last edited by

                        How the hell is 55039 related to the topic???

                        1 Reply Last reply Reply Quote 0
                        • M Offline
                          madmontero
                          last edited by

                          you said "delete the crap you created" ???

                          Let me spool up another fresh VM and try it…  :-\

                          1 Reply Last reply Reply Quote 0
                          • D Offline
                            doktornotor Banned
                            last edited by

                            Maybe someone else. IMNSHO, if you cannot tell WAN from LAN and client from server, you should keep your hands miles off any firewall. The default LAN rule allows all traffic go out from LAN (such as Outlook communication with mailserver on WAN). There is absolutely zero need to open anything else, to create any portforwards on LAN or any similar nonsense.

                            1 Reply Last reply Reply Quote 0
                            • H Offline
                              hda
                              last edited by

                              @madmontero:

                              …
                              Actually ALL ports are pretty much blocked!
                              ...

                              You do not need to open up WAN to send & pop email. So yes your ports from outside are blocked.

                              1 Reply Last reply Reply Quote 0
                              • D Offline
                                doktornotor Banned
                                last edited by

                                And BTW, you should use 587 for sending email and 995 (POP3/S) for downloading email. Not send out your credentials in plaintext. (Also, at least TCP/25 is blocked tons of ISPs.)

                                1 Reply Last reply Reply Quote 0
                                • M Offline
                                  madmontero
                                  last edited by

                                  @doktornotor:

                                  Maybe someone else. IMNSHO, if you cannot tell WAN from LAN and client from server, you should keep your hands miles off any firewall. The default LAN rule allows all traffic go out from LAN (such as Outlook communication with mailserver on WAN). There is absolutely zero need to open anything else, to create any portforwards on LAN or any similar nonsense.

                                  Thanks! this is what I was looking for.. just an easy, simple explanation.

                                  As for the 587/995… They don't use this...This is from GoDaddy

                                  Next to Outgoing Server (SMTP), type 465. Click OK and click Next.
                                  If those settings don't work,repeat steps 1-3 and select None for Use the following type of encrypted connection. Try these other ports for Outgoing server (SMTP): 80, 3535, or 25

                                  HDA, thanks for the response.. again, these are just a few client machines that need to access pop/smtp email from behind the PFsense.

                                  I'll let you guys know in a bit!

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ Offline
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by

                                    agreed 25 outbound to everything other than the ISP smtp servers is blocked on many isps..  You can thank the spammers and malware/viruses that turn boxes into spam senders for that.

                                    "Incoming mail server    pop.secureserver.net
                                    Outgoing mail server (SMTP) smtpout.secureserver.net"

                                    If you have clients behind pfsense on your lan that need to talk to those servers outside pfsense, ie the internet (wan) then you have nothing to do with port forwards or specific rules if you have the default any any rule on the lan.  This allows lan clients to talk to anything on the internet, ports or protocols.

                                    If you can not talk to those servers on 25 and or 110 then talk to your ISP..  But as stated you shouldn't be using 25 or 110 to talk to that mail server outside anyway - as dok stated you should use secure methods so your username and password is not sent in the clear across the public net.  The 587 is normally allowed by isps while 25 is not.

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

                                    1 Reply Last reply Reply Quote 0
                                    • H Offline
                                      hda
                                      last edited by

                                      @madmontero:

                                      Thanks! this is what I was looking for.. just an easy, simple explanation.

                                      Again, read a few easy knowhow bytes.

                                      You need the allow-rules row (2 & 3) in your Firewall: Rules LAN. And delete (1, 4 & 5)
                                      Empty Firewall: Rules Floating()

                                      IF you do not appreciate initiative from global or not serve to global, then:
                                      Empty Firewall: Rules WAN()
                                      Empty Firewall: NAT: Port Forward()

                                      1 Reply Last reply Reply Quote 0
                                      • M Offline
                                        madmontero
                                        last edited by

                                        Thank you guys for the help! I got it working.. did exactly as you (ALL) said and everything is cool  8)

                                        I"m used to working on Sonicwall NSA's and Fortigate's but just have this running at one site and it's been fine forever until this upgrade. I thought it was corrupted.

                                        Thanks again for all your help! Even DOK  ;)

                                        1 Reply Last reply Reply Quote 0
                                        • 2 Offline
                                          2chemlud Banned
                                          last edited by

                                          Fine! :-)

                                          Would you mind sharing your firewall ruleset for a final check here?

                                          Just to confirm that all issues are fixed!

                                          1 Reply Last reply Reply Quote 0
                                          • M Offline
                                            madmontero
                                            last edited by

                                            So here's my final config.. pretty barebone.. one thing I was going to hit up Johnpoz on or post in the VM forum is my Intel NIC card (dual GbE server) seems to just be turning off or shutting down now after some heavy use. e1000 drivers. Never did this on straight 5.5 and prev PF version. I only upgraded to U2 to run 2.2.2

                                            And just FYI.. I bought like 5 of these years back.. been working fine on my ESXi and Windows boxes. Just now it's crapping out on PFsense.

                                            Thanks!

                                            http://www.ebay.com/itm/271581912527?_trksid=p2060353.m1438.l2649&ssPageName=STRK%3AMEBIDX%3AIT

                                            P.S. I just Disable hardware checksum offload to see if that helps or does anything.

                                            Nat-portFWD.PNG
                                            Nat-portFWD.PNG_thumb
                                            FW-rulesWAN.PNG
                                            FW-rulesWAN.PNG_thumb
                                            FW-rulesLAN.PNG
                                            FW-rulesLAN.PNG_thumb
                                            vswitch.PNG
                                            vswitch.PNG_thumb

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.