Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I open the ports 21 , 3389 and any other port but it show me that they are close why?

    Scheduled Pinned Locked Moved Firewalling
    40 Posts 5 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @nihad123
      last edited by

      @nihad123 said in I open the ports 21 , 3389 and any other port but it show me that they are close why?:

      @jahonix modem fibre

      Are you sure its running in modem mode ?

      What is the make and model ?

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      N 1 Reply Last reply Reply Quote 0
      • N
        nihad123 @NogBadTheBad
        last edited by

        @nogbadthebad said in I open the ports 21 , 3389 and any other port but it show me that they are close why?:

        I’m guessing there is a WAN router further upstream from your pfSense router.

        I have router-----pfsense----windows_servers2012

        1 Reply Last reply Reply Quote 0
        • N
          nihad123 @NogBadTheBad
          last edited by

          @nogbadthebad yes pfsense en modem mode because all machine after pfsense have ip adresse from the adressage plage of dhcp that i define to lan pfsense, I want say that machine after pfsense has 10.0.0.15 10.0.018 ... and it connect to the internet

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            You have to forward incoming access to pfSense WAN address (192.168.1.44) now, of course if the router isn't in modem / bridge mode.

            If pfSense does all the filtering now, you can forward all incoming traffic to it. Some routers have a DMZ option for that, others call it "Exposed host".

            N 1 Reply Last reply Reply Quote 0
            • N
              nihad123 @viragomann
              last edited by

              @viragomann I changed anything on my router so I think that it is inin modem mode , so I will forward incoming access to pfsense wand adress 192.168.1.44, and after that what I will do on nat and rules pfesense?

              1 Reply Last reply Reply Quote 0
              • V
                viragomann
                last edited by

                Yes. But I don't think your router is in modem mode.

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad
                  last edited by

                  What exactly is the make and model of the upstream device?

                  What is the connection into it, ADSL, Ethernet, ... ?

                  Do you have access to this device to change its config ?

                  The issue here is the device between the Internet and your pfSense box.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  N 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    @nihad123 said in I open the ports 21 , 3389 and any other port but it show me that they are close why?:

                    I think that it is inin modem mode , so I will forward incoming access to pfsense wand adress 192.168.1.44

                    If your isp device was in "modem" mode then pfsense wan would be a public IP - not a rfc1918 address.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    N 1 Reply Last reply Reply Quote 0
                    • N
                      nihad123 @NogBadTheBad
                      last edited by

                      @nogbadthebad modem fibre optique yes i have access o the modem and i can make any changes on yes I know, so what can I do? I Give it ip adresse public to wan of pfsense or what? and if I give the ip public to wan pfsense I don't know any adress gatway upstream should give to interface wan pfsense

                      1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad
                        last edited by

                        Maybe google the modem make, model and pfSense and see if anyone has managed to get it working.

                        You then need to set up pfSense to probally connect to the modem via PPPOE.

                        People keep trying to help you here and your not answering the questions.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          nihad123 @johnpoz
                          last edited by

                          @johnpoz and if I give the ip public to wan pfsense I don’t know any adress gatway upstream should give to interface wan pfsense, and how can I know if my divice between internet and pfsense is in modem mode

                          1 Reply Last reply Reply Quote 0
                          • N
                            nihad123 @NogBadTheBad
                            last edited by

                            @nogbadthebad the modem connect via pppoe and have an address ip public unique and I find "dmz host " so what's ip that i will fill in? I fill the ip adress of pfsense wan, 192.168.1.44 or what exacteley?

                            NogBadTheBadN 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              if your isp device allows for dmz host, then sure you can put pfsense wan IP as that.. Then any traffic that hits your public IP should be sent to pfsense - then your pfsense forwards would work.

                              But I would HIGHLY suggest against opening up rdp to the public internet. If employees need to get into the work network while they are home on the road, then they should VPN in. Then they can access what they need securely.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              N 1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN
                                NogBadTheBad @nihad123
                                last edited by NogBadTheBad

                                @nihad123 said in I open the ports 21 , 3389 and any other port but it show me that they are close why?:

                                @nogbadthebad the modem connect via pppoe and have an address ip public unique and I find "dmz host " so what's ip that i will fill in? I fill the ip adress of pfsense wan, 192.168.1.44 or what exacteley?

                                Try setting the device into modem mode and configuring the pfSense WAN interface like this:-

                                0_1530114554409_Untitled.jpeg

                                0_1530114565591_Untitled2.jpg

                                Don't enable IPv6

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                N 1 Reply Last reply Reply Quote 0
                                • N
                                  nihad123
                                  last edited by

                                  @viragomann I have the dmz hoste so what I will fill in? the ip adress of pfsense wan? 192.168.1.44?

                                  the model of my dvice is F660

                                  1 Reply Last reply Reply Quote 0
                                  • V
                                    viragomann
                                    last edited by

                                    Yes, the address of pfSense WAN interface. Already mentioned that here.

                                    1 Reply Last reply Reply Quote 0
                                    • N
                                      nihad123 @NogBadTheBad
                                      last edited by

                                      @nogbadthebad I make the same password that I put when I want login to my PPPoE? or I choose an password?

                                      1 Reply Last reply Reply Quote 0
                                      • NogBadTheBadN
                                        NogBadTheBad
                                        last edited by

                                        @nihad123 said in I open the ports 21 , 3389 and any other port but it show me that they are close why?:

                                        F660

                                        My screenshots are for if you've set the router device to modem mode with PPOE.

                                        Same user ID & password as on the F660.

                                        Andy

                                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                        1 Reply Last reply Reply Quote 0
                                        • N
                                          nihad123 @johnpoz
                                          last edited by

                                          @johnpoz ok I allows for dmz host 192.168.1.44 and on my pfsense what's rules and nat that I will allows?

                                          1 Reply Last reply Reply Quote 0
                                          • NogBadTheBadN
                                            NogBadTheBad
                                            last edited by

                                            STOP

                                            Are you going to use a DMZ or put your F660 into modem mode?

                                            Andy

                                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                            N 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.