Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT Problem!

    NAT
    3
    8
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tienbm
      last edited by

      Dear all,
      I have problem:

      • Client(10.0.0.5) cannot call to IP WAN + port 80 of Client(10.0.0.10) but Client(10.0.0.5) can ping to Client(10.0.0.10).

      How do I do for resolve problem  :'(?

      Thanks!
      aaaaa.png
      aaaaa.png_thumb

      1 Reply Last reply Reply Quote 0
      • K
        kobzar
        last edited by

        Check your firewall rules first for WAN port on Pfsense.
        Second, on the Interfaces ==>> WAN settings page
        unselect
        "Block private networks and loopback addresses"
        and
        "Block bogon networks"

        WatchGuard x750e + 2GB + SATA-IDE 320GB

        1 Reply Last reply Reply Quote 0
        • T
          tienbm
          last edited by

          Hi kobzar,

          • From outside can connect to port 80 of client (10.0.0.10 ) => Rule on WAN interface is correct.
          • On Wan Setting page, I unselected two option "Block private networks and loopback addresses" and "Block bogon networks", but I have recived the same problem.

          Thanks.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            your drawing shows a duplicate IP client 2 is 10.0.0.10 and then your trying to port forward that same address port 80 to something behind it.. that you hide???  WTF for?

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • T
              tienbm
              last edited by

              Hi johnpoz,
              Client 10.0.0.10 forward port 80 over Public IP of WAN Pfsense and then Client 10.0.0.5 call to WANIP port 80 but not success!

              Thanks.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                what???  Makes ZERO sense..  Clients don't forward ports…

                You have clients inside your transit network to the internet.. According to your drawing the wan IP of pfsense in this 10.0.0/? transit is 10.0.0.10, and then you also have a client with that same 10.0.0.10 address..

                Post up your port forwards from pfsense.. And what is the IP of your device trying to access your forward..  Where is pfsense forward port 80 too??  What IP??  Something behind it??

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • T
                  tienbm
                  last edited by

                  Hi,
                  I tried explaint the topology on attach file.

                  Thanks.

                  pfsense.jpg_thumb
                  pfsense.jpg

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    That drawing is horrific!!!

                    So your clients are behind pfsense on a 10.0.0/24 network??

                    So pfsense wan is 125.x.x.x.. So you have a client trying to hit your webserver via your public IP..  For that to work you have to have setup NAT reflection.  But if your client on 10.0.0.5 wants to talk to client 10.0.0.10 why you not just resolve abc.com to 10.0.0.10 on pfsense via a host override!!

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.