Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Minecraft Server Inside my pfSense box

    Scheduled Pinned Locked Moved Gaming
    15 Posts 4 Posters 10.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Nobody is scoffing at you.  Considering how most of us are network professionals who use pfSense in corporate environments, I doubt anyone here has any experience running Minecraft on pfSense.  As part of our advice, we generally try to steer people away from things that aren't best practice.  I've only been here for a little more than 2 years and I have never heard of anyone doing what you are trying to do.  It may very well be possible to run MC on the firewall itself, with only a single WAN rule to allow access, but I've never done it so I can't really advise you as to how to do it successfully.  Try adding a WAN rule:

      Proto: IP4 TCP/UDP
      Source: Any
      Dest: WAN address
      Dest port: (other) 25565

      1 Reply Last reply Reply Quote 0
      • T
        thejtshow
        last edited by

        Thank you very much! I will try this out when I get home. I also appreciate you giving me a bit of context to the people of this forum; I had assumed that there would be more enthusiasts on here. My apologies if I had offended anyone.

        I am more of a tinkerer and a see if I can do this kind of person, and will be trying to learn more about this tool as I get more time to read up on it and networking in general.

        Thanks,
        Justin

        –------------------------------------------------------------------

        Tinkering with things I shouldn't


        1 Reply Last reply Reply Quote 0
        • KOMK
          KOM
          last edited by

          There are a lot of home users and tinkerers here, but typically the people with a lot of posts and high karma are the more experienced users and often network professionals.

          If my suggestion doesn't work, come back and post your firewall log output.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            pfSense is simply not the right tool for that job.

            You would probably be happier installing Ubuntu on your hardware and just port forwarding a port on your linksys/dlink/tplink router.

            Or installing a hypervisor and running pfSense alongside Ubuntu.

            pfSense is not your typical "distro" and people often try to make it do too much. It does what it is designed to do very well.  Hosting a game server isn't that.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • T
              thejtshow
              last edited by

              I do appreciate the sound advice of using things for what they are optimized for – and not using them for what they are not. I do not plan to use this as my permanent minecraft server or host it for more than a handful of friends -- My more permanent solution will be a hypervisor sort of setup.

              Kom thank you for being patient and providing a pragmatic answer - I will keep you posted if only to satisfy a bit of curiosity you might have :)

              –------------------------------------------------------------------

              Tinkering with things I shouldn't


              1 Reply Last reply Reply Quote 0
              • T
                thejtshow
                last edited by

                Success!!!! For now..

                I implemented your rule, pointing the wan connection to self (this was really the question I had - whether this setting existed or would it just endlessly redirect…) and was able to see your server in my list to connect to (with a 17 ms ping). However, when I connected to it (or attempted to), the connection timed out and I was locked out of the web configurator as well.

                At this point I was typing up a very sorrowful concession of defeat on this post.. until I remembered I had just installed snort and thought that might be actually doing its job and keeping out weird connections. Turns out this was the case.. though I haven't the slightest idea of how to configure snort efficiently at all let alone place an exception for these types of connections... Alas, this server is serving its purpose in letting me learn about networking and pfSense, in a rather roundabout fashion. But it does work, and takes very little resources. I have the JVM limited to 2 GB (out of 6) and with just me on it the CPU was running at about 3%.

                So, to answer my own burning question (with the much needed help of KOM)... YES. You can run a Minecraft server on your pfSense machine.

                This is where I would like to know what potential security hazards doing such a task would open me up to, aside from the fact that minecraft can quickly turn into a resource hungry animal.

                Thanks again for being a good community, sorry for being a bit brash at first. I look forward to learning a lot from you guys and my experiences with pfSense. Fingers crossed my roommates will let me use it as my main router/firewall.

                for anyone interested in what I did, I have openjdk 1.8_72 running minecraft 1.8.9 on a screen that I executed from the shell built into pfSense, and KOM's WAN rule above pointed to self (this firewall).

                Thanks again,

                J.T.

                EDIT -- it bothered me so I went hunting for a proper snort setup guide. Followed the instructions here (https://forum.pfsense.org/index.php?topic=61018.0) and the server works through the firewall no problem. I think I had two rule sets turned on before and/or set my policy to restrictive. Serves me right for just toying with settings and "what looks right."

                So mission accomplished. Cool.

                –------------------------------------------------------------------

                Tinkering with things I shouldn't


                1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM
                  last edited by

                  I wasn't sure if using WAN address vs This Firewall would make any difference.

                  I used to run a fully-featured Minecraft server (Craftbukkit, 30+ plugins) for a bunch of local kids on my VPS, but I had to shut it down because I needed the resources for other services and didn't want to pay more per month for the server.

                  Glad to hear you got it working.

                  1 Reply Last reply Reply Quote 0
                  • T
                    thejtshow
                    last edited by

                    Alrighty - anyone well versed in scripting? The next step to this process would be automating the launch of the minecraft jar. I have tried making a script.sh and adding it to shellcmd, and dumping it directly into the rc.d directory. the permissions on that script are 777.. still nothing happens. any ideas?

                    Thanks

                    –------------------------------------------------------------------

                    Tinkering with things I shouldn't


                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      This question is more suited to a Minecraft forum.

                      http://minecraft.gamepedia.com/Tutorials/Server_startup_script

                      1 Reply Last reply Reply Quote 0
                      • J
                        JuantonJohn
                        last edited by

                        Very cool you were able to get this to work.  8)

                        I have found pfSense will do really strange things if it doesn't like the setup (hardware, usually).  Fair warning if you start getting strange results.

                        Since your problem solution seems to be very unique, please post as much details as possible about what you followed to make this happen.  Others may find this very useful in the future.
                        Links to openjdk
                        Quad port model # used.
                        Rules used / not used, etc.
                        Network layout.

                        Have fun and good luck.

                        1 Reply Last reply Reply Quote 0
                        • T
                          thejtshow
                          last edited by

                          Of course.

                          1. openjdk
                              a. https://www.freebsd.org/java/
                              b. pkg install openjdk8

                          2. Minecraft
                              a. I followed this guide, but instead of sudo apt-get, I just used pkg: https://www.digitalocean.com/community/tutorials/how-to-set-up-a-minecraft-server-on-linux
                              b. note that if you run the commands from root or from a script, it may create all the minecraft files in an unexpected directory.. Most likely just an operator error on my part but all my files ended up in my /root directory instead of my /minecraft one.

                          3. pfSense rules
                              a. Create a new firewall rule
                                    i. interface WAN, protocol TCP, source ANY, Destination THIS FIREWALL(SELF), Port Range from (OTHER) 25565 to (OTHER) 25565

                          thats about it. the NIC I am using is an intel pro 1000 pt gigabit quad port interface card, I believe the 9490 model.. and my machine is a Dell Optiplex 790 with an i5 and 6 GB of mixed ram (2x2 + 2x1). I can access the minecraft server from both LAN and WAN, which is nice. Anything else just ask. Still working on the autorun script issue.. oh well.

                          –------------------------------------------------------------------

                          Tinkering with things I shouldn't


                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.