Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't turn off default Deny Private Networks rule

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 2 Posters 1.5k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Online
      johnpoz LAYER 8 Global Moderator
      last edited by

      Lets see your wan rules and your port forward.

      Dest would be pfsense wan address because its going to "forward" that it sees to it, to the IP behind pfsense.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07 | Lab VMs 2.8, 25.07

      1 Reply Last reply Reply Quote 0
      • M Offline
        mark hisel
        last edited by

        NAT
        interface WAN
        protocol TCP
        Src Add *
        Src Port *
        Dest Add WAN Address
        Dest Port 50051
        NAT IP 192.168.40.3
        NAT Port 50051

        RULES
        protocol IPv4 TCP
        source alias includes dhcp IPs from wireless router
        port *
        dest WAN Address
        port 50051
        gateway *

        1 Reply Last reply Reply Quote 0
        • M Offline
          mark hisel
          last edited by

          NAT source port must also be 50051 apparently; it doesn't get through when set to ANY

          1 Reply Last reply Reply Quote 0
          • M Offline
            mark hisel
            last edited by

            Do I need a Pass rule on LAN? I tried this but it hasn't worked

            protocol IPv4 TCP
            source LAN Address
            port *
            dest LAN Net
            port 50051
            gateway *

            1 Reply Last reply Reply Quote 0
            • johnpozJ Online
              johnpoz LAYER 8 Global Moderator
              last edited by

              picture is WAY better dude...

              Source of 50051 would be included in ANY ;) So not sure what your thinking..

              Post a screenshot!

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • M Offline
                mark hisel
                last edited by

                Turns out pictures take too much skill

                Yeah, I though ANY would work, but it doesn't get into the logs when I do that. If I put the port number in there it does. go figure.

                ok I figured out how to upload a picture. pretty cool.
                0_1552266748441_NATrules.png image url)

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  So your port forward is not linked to your wan rule.. Why did you uncheck let it create the rule for you..

                  And what is the table for your privatewireless? alias?

                  This is what the rules should look like

                  0_1552267174572_portforward.png

                  Sure you can put in your alias as source if you want.. But really you have boxes on your own network wan wifi that you need to block?

                  Why did you change this?
                  0_1552267382034_whydidyouchange.png

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    mark hisel
                    last edited by

                    I can't really be held responsible for what I may or may not have done you see, there's a lot of mystery and confusion over here I have to deal with.

                    So I need to have a link - now we're getting somewhere. Can you tell me how to do that or point me to docs? I guess now that you've clued me in to that I can maybe find out. Thanks!

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      mark hisel
                      last edited by

                      Or start over and let pfSense do it

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        mark hisel
                        last edited by

                        Right On johnpoz!!!

                        Android just got a response from the server!
                        Thank you very much!! You know, it seems like it should be easy, but it's kind of like driving through a new city on a complicated freeway. It's pretty easy to get overwhelmed. Thanks again !!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.