Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ring video doorbell behind PFsense firewall?

    Scheduled Pinned Locked Moved Firewalling
    28 Posts 13 Posters 16.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jeauxbleaux
      last edited by

      Here are the two responses I got from Ring.com to my query:

      Jun 6, 5:33 AM PDT

      Hello,

      Thank you for contacting us. I apologize but the information that you are asking for us to
      provide is proprietary. The only public information of what you are asking is the link
      that you have sent in.

      –-----------

      And another one:

      Jun 4, 1:53 PM PDT

      Hi there!

      Just open up all out going and incoming and there are no Ip's that cn be white listed
      cause the always change.


      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        @jeauxbleaux:

        Here are the two responses I got from Ring.com to my query:

        Thank you for contacting us. I apologize but the information that you are asking for us to
        provide is proprietary. The only public information of what you are asking is the link
        that you have sent in.

        Firewall ports are proprietary? Good luck, Ring.

        Hi there!

        Just open up all out going and incoming and there are no Ip's that cn be white listed
        cause the always change.

        Just open all the ports inbound and don't source limit.

        That person should not be allowed near a customer network in any capacity.

        Out of curiosity, did your ring not work or are you just wondering about their answers?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • J
          jeauxbleaux
          last edited by

          Both.

          Everything seems to work -except- the live video from the RING to my android phone…arguably the most significant function.  The Ring android app is currently installed as-is; I haven't firewalled or app-limited it in any way (yet)  (though why they need access to my contacts list, passwords, phone, location, etc, etc, etc is beyond me.  I'm betting they don't; they just got somebody in bangalore-or-wherever to 'whip up' an app for them quick and cheap).  So the app is (apparently) not the problem.  Though all of my firewalls in all the places I normally hang out are pretty fascist (I know because I set most of them up); I supposed the incoming video to my phone from their [proprietary] servers could be blocked from there.

          So yes, I was curious about their answers too. Their answers, plus the intrusive app, tell me that they're dismissive about network and systems security and stablity.  That doesn't leave me all warm and fuzzy so I'm sending it back.

          Just as a datapoint, I took a quick look at Skybell (a competitor) and they're even less informative.  I did see a comment that someone was complaining that he couldn't DHCP assign anIP to his skybell.  When asked about it he said Skybell says they 'rotate MAC's as a security measure' .

          1 Reply Last reply Reply Quote 0
          • P
            pitmancd
            last edited by

            I have a new Ring Video Doorbell Pro, couldn't get it to work, similar problems listed here, even though I have an ASUS router.  I hope this info helps someone else as I got my issues resolved simply by turning off NAT acceleration, also referred to as hardware acceleration, CTF (Cut-Through Forwarding), or FA (Flow Accelerator).

            You can read more about this "feature" here:

            https://routerguide.net/nat-acceleration-on-or-off/

            For ASUS routers, go here in the router's settings:  LAN -> Switch Control -> NAT Acceleratinon -> Disable.

            BTW, things that I tried that didn't make a difference inlcude:  enabling WAN ping, setting the doorbell to a static IP, setting the doobell's static IP as the DMZ, disabling the firewall completely, port forwarding all ports as suggested by Ring tech support.

            1 Reply Last reply Reply Quote 0
            • H
              huthmakerj
              last edited by

              In case anyone is still wondering about this.  I have a Palo Alto firewall and had issues with my new Ring Elite.  Took about an hour to figure out.  I had to disable SIP inspection on the firewall.  Its likely the same issue for everyone here.

              1 Reply Last reply Reply Quote 0
              • N
                niebla
                last edited by

                My ring doorbell works fairly well with PFsense. The problem seems to be associated with the windows client which is slowly being updated. Be sure to assign a static IP address, exclude from squid, and possibly a custom NAT depending on your config. The doorbell needs unrestricted access out.

                1 Reply Last reply Reply Quote 0
                • ?
                  Guest
                  last edited by

                  I have a Ring doorbell too, made sure that it gets an assigned address and it's working perfectly.

                  The only issue I have is that on one of my two Android phones, the alert takes about 5 minutes to come through. My wife has two iPhones and they work perfectly well, it's just the one Android device that is delayed. Must have some strange routing via Mars or something.

                  1 Reply Last reply Reply Quote 0
                  • N
                    niebla
                    last edited by

                    Is the Android slow on wifi and 3/4g? Please test individually by disabling the other and report back.

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      I have two Android phones, only one of them is slow.

                      Actually, someone just rang the bell, so this time the delay between the two phones was about 2 seconds, but it has been up to five minutes.

                      I'll check it out later on wifi and 3/4G and see which one has the issue.

                      1 Reply Last reply Reply Quote 0
                      • A
                        A.Bursell
                        last edited by

                        I also recently installed a Ring doorbell. On my home wifi, same network as Ring, it works great. I did not do anything extra with pfSense. It is setup on a multi-WAN setup with 3 AT&T hotspots to an SG-2440 with latest pfSense to a Netgear X4 wifi router.

                        On cell service it works great.

                        At my parents home, it sometimes works great and other times not. The setup there is a Comcast cable connection to a APU2D4 with latest pfSense to a Netgear WNDR4500 wifi router.

                        To clarify, I am now talking about going through my parents network to the Ring system to my home network.
                        If I start with a fresh reset of pfSense the app will load instantly and everything works great - alerts and live video. Over time, sometimes a day or two, something happens where I try to load the app and it will take probably 30 seconds before it loads. Once loaded it works well enough, though a little slower I think. And alerts are slow. But if I reset the pfSense router it will work fast again like it should. I have not adjusted anything on this pfSense box either.

                        That is my experience and so far I have not been able to find the problem. Actually I can't even tell what's different. I tried resetting states and made no difference. But resetting the whole box will correct it.

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Reset which router?

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • A
                            A.Bursell
                            last edited by

                            @Derelict:

                            Reset which router?

                            I have only ever needed to reset the pfSense router at my parents house. That is the only place it sometimes doesn't work. Works great from my house (same network as ring) and great from cell data.

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Not running anything like squid there? It should just be an outbound connection to ring I figure.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • A
                                A.Bursell
                                last edited by

                                @Derelict:

                                Not running anything like squid there? It should just be an outbound connection to ring I figure.

                                Nothing else, just the basics. I think about the most I have configured is using Google DNS for clients. Actually using it for IPv4 and IPv6. But otherwise pfSense is pretty much how it installed. No changes to firewall or anything else that I recall. Which is why it's strange that it works great most of the time, but will occasionally seem to get hung up and require a reboot to get the app back up to speed.

                                1 Reply Last reply Reply Quote 0
                                • DerelictD
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  Yeah. there is nothing that rebooting the firewall would clear there.

                                  It could be something with IPv6. If a device thinks it has IPv6 it will generally try to use that first. If it is broken it will fall back to IPv4 if available. That is a common cause of things that "take 30 seconds to load."

                                  That is where I could concentrate at first.

                                  It also sounds like you might be double-NAT there. Should work but might also be a place to look.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    A.Bursell
                                    last edited by

                                    Oh good idea, I hadn't really thought about IPv6. I don't have it on my home network and everything works even with my unavoidable multi-NAT setup. My parents have Comcast (no double-NAT, modem in bridge mode and Netgear as AP) and it has IPv6. I didn't really think I had to do anything since pfSense just worked so all I did was add Google DNS. Maybe I'll play with it more. I don't really know much about it but sounds like it's time to learn.

                                    Thanks for your help!

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      tonykakkar Banned
                                      last edited by tonykakkar

                                      This post is deleted!
                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        timleibovich
                                        last edited by

                                        FYI, I was able to get this to work by disabling my DNS Resolver and enabling the DNS Forwarder service instead. I didn't need to add any additional Firewall rules or NAT/PAT rules since all of the connections are initiated outbound.

                                        I don't have a good idea what about the DNS Resolver the Ring was incompatible with, but wanted to put this out there so if others want, they can track down the cause.

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.