Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port being blocked

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 5 Posters 792 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mgodinez
      last edited by

      Hi everyone,
      I have started using pfsense on a network that has an AC server to be able to control the house AC, but for some reason, it is blocking web access to it. I can PING the address and get the results just fine, BUT when I use the browser to mess with the configuration of the AC, it won't find the server, it is just like is not there at all. I was using another router and it worked just fine with it. Now that I have replaced it with PfSense latest version, well it is not letting me access the AC's browser interface.
      Any ideas what is causing this? The address is 192.168.2.230 and the port is 32032 - Just so you know how the web interface is being accessed. Thanks in advance!

      Regards

      Manny G.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Inter-LAN communication doesn't hit the firewall at all. Is the client on the same subnet as the AC server?

        1 Reply Last reply Reply Quote 0
        • M
          mgodinez
          last edited by

          I haven't checked the AC server settings but I am guessing it is because if I exchange the PfSense with the original router that it was in place before, it works, but once I place the PfSense instead, it stops working, I CAN ping it BUT not connect to the web interface at all. I am using the same client computer to access the AC server and when using the original router (Which is only a router NAT becuase I have another computer running windows server 2008 R2 running DHCP/DNS/File servers) works just fine, but when using the PfSense, it stops working, again I can still ping it BUT no web interface at all.

          Manny G.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            What are the LAN settings for both your client and the AC server? You can't be guessing here to try and debug a network problem. It would also be helpful for you to draw a simple network diagram showing what's connected to what and upload it here. You can upload images directly without needing to put them on Imgur and linking to it.

            1 Reply Last reply Reply Quote 0
            • M
              mgodinez
              last edited by

              Here is a small diagram

              https://www.screencast.com/t/SIBDlaq64

              Hope that helps explain what I have.

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by

                Looks like everything is on the same subnet, it's not a pfSense issue.

                Is the subnet mask consistent across all the devices, i'm guessing they are a /24.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Yea as mentioned pfsense has ZERO to do with devices on the same network, in your case 192.168.2/24 talking to each other...

                  The only thing that comes to mind to why it worked with your old router and not with pfsense is you were doing nat reflection on your old router..

                  Ie hitting your public IP for your webserver your trying to access, for it to be reflected back in.. This is BAD practice and should be avoided.. But if you want to do that then you would have to set it up on pfsense, its not going to do that automatically like some soho routers do.

                  But if your going to http://192.168.2.230:32032 or http://host.something.tld:32032 where host.something.tld resolves to your 192.168.2.230 address then pfsense has zero to do with it.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • M
                    mgodinez
                    last edited by

                    Thanks for the reply guys, well, I did place the old router back and removed PfSense and noticed that the browser now it didn't get the web interface of the AC server, until I had to type the whole url (e.g. http://192.168.2.230:32032/cgi/login ) which seems strange. I am too stumped of why it works with the old router and not PfSense. I haven't tested yet the full url but I am wondering....

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @mgodinez
                      last edited by

                      @mgodinez said in Port being blocked:

                      I am too stumped of why it works with the old router and not PfSense.

                      But just before that you said :

                      @mgodinez said in Port being blocked:

                      well, I did place the old router back and removed PfSense and noticed that the browser now it didn't get the web interface of the AC server,

                      So, even with the old router you didin't get to the web interface of the AC server ..... right ?
                      So : the old router works - or it didn't ?

                      @mgodinez said in Port being blocked:

                      I had to type the whole url (e.g. http://192.168.2.230:32032/cgi/login ) which seems strange.

                      Strange ?
                      This is how the things works since the earlier seventies (last century).
                      In the address bar of your browser you have to use an IP (IPv4 or IPv6) address, or, if you gave your device (192.168.2.230) a A record in the local DNS, an URL like
                      http://my-local-server.local.lan/cgi/login

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.