Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Could not SSH from WAN

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 6 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Post screenshots of your WAN firewall rules and your port-forward NAT rules.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        "This confirms the issue to be with the firewall settings."

        Or it could be firewall on the NAS that only allows access from local network.

        Lets see your port forward, lets see your firewall rules.

        This is in reality 10 seconds to configure.  Port forward to your private IP = done, it will by default create the wan rule for you.

        Go to canyouseeme org and test it.  If doesn't work then use the port forwarding troubleshooting doc https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

        sshportforward.png_thumb
        sshportforward.png

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • ?
          Guest
          last edited by

          I had this SSH setup using D-Link firewall before replacing. With pfSense I spent 2 days without success..

          Dude, there are worlds between them!

          1 Reply Last reply Reply Quote 0
          • J
            Josh2440
            last edited by

            Thanks for all the reply.

            I use a remote server to test SSH. Last night I got it working by changing "Destination port range" to SSH and "Redirect target port" to 700. I logged in using port 22 from the remote server.

            Previously I had the "Destination port range" to 700 and tried to ssh -p 700 from the server. According to the documents this should have worked fine but I have no idea why pfSense will not forward port 700 or any other ports I tried before.

            Is this a bug?

            1 Reply Last reply Reply Quote 0
            • J
              Josh2440
              last edited by

              Redirect Target Port: The internal port where this traffic will be forwarded, and is usually the same as the external port as defined in Destination port range. If multiple ports in a range are used for the Destination port range, this is the starting port of the range as it must be the same size range.

              https://doc.pfsense.org/index.php/How_can_I_forward_ports_with_pfSense%3F

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                @Josh2440:

                Thanks for all the reply.

                I use a remote server to test SSH. Last night I got it working by changing "Destination port range" to SSH and "Redirect target port" to 700. I logged in using port 22 from the remote server.

                Previously I had the "Destination port range" to 700 and tried to ssh -p 700 from the server. According to the documents this should have worked fine but I have no idea why pfSense will not forward port 700 or any other ports I tried before.

                Is this a bug?

                No. It works for everybody but you.

                If you would rather use 700 than 22, put it back, confirm it doesn't work as you're expecting, and post what you did.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • J
                  Josh2440
                  last edited by

                  Bunch of rsync jobs are queued from the server to NAS. When its done I'll replace Destination port range to 700 and ssh -p 700 from the server and update the findings.

                  But that's how I was trying before… using same Destination & Redirect Target Port

                  1 Reply Last reply Reply Quote 0
                  • D
                    doktornotor Banned
                    last edited by

                    Hmm, but rsync uses 873/TCP. Plus, when using rsync over SSH, SSH needs to be actually running on the port you are trying to use. Sigh, no idea what are you trying to do.

                    1 Reply Last reply Reply Quote 0
                    • J
                      Josh2440
                      last edited by

                      my files are getting backed up without errors. coming through port 22 forwarded to 700

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        Wonderful. You just told us it doesn't work in the first post. Well, good luck.

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Yeah.  I rsync over SSH to my NAS all the time.  All on ports other than 22:

                          WAN:8022 -> 192.168.1.100:22
                          WAN:8023 -> 192.168.1.101:22
                          WAN:8024 -> 192.168.1.102:22
                          etc
                          etc

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.