Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No Internet access for my Synology

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    19 Posts 5 Posters 9.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      raga
      last edited by

      I didn't do anything that's why it is strange and becoming "personal". no VLAN, all my devices like pc, raspberry pi, tv and av receiver are connected to an 8 port switch and all of them have internet access.

      I can ping my Synology from the firewall

      ![Screenshot from 2016-08-24 13-15-16.jpg](/public/imported_attachments/1/Screenshot from 2016-08-24 13-15-16.jpg)
      ![Screenshot from 2016-08-24 13-15-16.jpg_thumb](/public/imported_attachments/1/Screenshot from 2016-08-24 13-15-16.jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        You have jumbo frames enabled.. Why??  But that is most likely your problem.  Did you set pfsense to be jumbo frames?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • R
          raga
          last edited by

          man you are right :).  :o jumbo frames was enabled on the old configuration and now with the new configuration the NIC doesn't support jumbo frames. thank you for your help

          1 Reply Last reply Reply Quote 0
          • R
            raga
            last edited by

            Now I have another problem, I cannot connect to my QuickConnect account meaning that I cannot use the cloud station, download station (all the services that use quickconect external access). I noticed that on the download station I can download but I cannot make upload. see the photos attached, in the one with QuickConnect I tried with both settings checked and unchecked the box "Automatically create port forwarding rules".

            any ideas on how to resolve this problem?

            Capture1.JPG
            Capture1.JPG_thumb
            Capture2.JPG
            Capture2.JPG_thumb

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              ""Automatically create port forwarding rules"."

              So you have UPnP enabled on pfsense if you want automatic port forwarding to happen?

              Clicked the advanced button - what are the ports it wants?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • R
                raga
                last edited by

                the UPnP is enable on pfSense. I managed to connect all my apps to the synology via ddns but quickconnect and updates still don't work. for the moment I will use the ddns account

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  what are updates - the syg going out and finding them?  not sure what quickconnect is.. is that something that suppose to work remotely or while your on the same l2?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • R
                    raga
                    last edited by

                    DSM updates - automatically updates. With QuickConnect, you can easily connect to your Synology NAS over the Internet without the hassle of setting up port forwarding rules or other complicated network settings. QuickConnect allows you to connect to DSM or some Synology packages using a customizable ID or address like quickconnect.to.

                    https://www.synology.com/en-us/knowledgebase/DSM/tutorial/General/How_to_make_Synology_NAS_accessible_over_the_Internet

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      well sounds like it has a problem finding home or phoning home that would allow for it too update and check in to let you know where to go for your quickconnect.

                      So manually checking for update doesn't work either I assume - if so sniff on pfsense when you do that and see what its trying to do that is not doing..

                      Maybe its trying to look up something via dns that you have blocked, or if your using unbound and their dnssec is broken will not return anything, etc.  Do you have any outbound rules blocking anything?  Are you using captive portal or proxy or something like snort or suricata, pfblocker?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • PippinP
                        Pippin
                        last edited by

                        Don`t use QC myself and never felt the need.
                        It can slow down speed substantially when going over the relay.
                        It uses various ways to try to establish a connection:

                        https://global.download.synology.com/download/Document/WhitePaper/Synology_QuickConnect_White_Paper.pdf

                        I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                        Halton Arp

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          Great link Pippin that seems to go over exactly how the qc works.. I just did a quick breeze and looks like from start it tries to do a nat hole punch.. That should fail since the client IP would not be the IP the state was opened too.  I think there might be a way to lower the restrictions on that.  But AFAIK that sort of method of opening up connection from the outside should fail..

                          The nat should be strict, if I syn opens a connection through pfsense to IP-A so my source port in that conversation is pfsenepublicIP:12345 –- publicIPA:qcport someone trying to use that connect from publicB should fail..  even if using the qcport as their source

                          publicIP-B:qcport ----> pfsenepublicIP:12345 should not be allowed.

                          If it is that is not a strict nat..  I will have to read over it more detail to try and figure out if any of their options should work or what you would have to do to allow them to work.  But real quick gut reaction to the first method and nat hole punching.. To be honest pfsense out of the box should block that.  Atleast I hope it does.  I have never actually tested it in a lab.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • R
                            raga
                            last edited by

                            I'm not using anything for the moment (I'm new to pfSense :) ), no outbound or captive portal or proxy. for the moment I will connect via ddns and I will look into the pdf that Pippin give us to see other ways and maybe more secure then free ddns :)

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              If you want my 2 cents, not a fan of opening this sort of stuff open to the public.  I just vpn into if need to access anything on my network be it files or plex server, etc.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.