Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    UPNP no routed between LAN and OPT1 interfaces.

    Scheduled Pinned Locked Moved Routing and Multi WAN
    10 Posts 3 Posters 931 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      g405tsh311
      last edited by

      Encountering a simple complex issue with pfsense. I have three servers on a subnet 172.16.11.x attached to OPT1 interface and clients on 172.16.10.x attached LAN interface. The rules on the interfaces (LAN and OPT1) are source port/IP and destination port/IP any any.

      I am trying to reach the servers in the OPT1 using UPNP. The issue is that the packets are not being passed between the LAN and the OPT1 interfaces. The firewall rules as allowing the packets to pass through without any issues. UPNP has been enabled and allow rules for 172.16.11.0/24 is allowed from ports 400-65535 for testing purposes. One server was connected directly to OPT1 and a client on the LAN side, still no UPNP connection.

      For every search in google library I found, it is mention that the by default pfsense should route between interfaces once a firewall rules are set, which they are. Still trying to get this working. The only time I can make UPNP work with pfsense is if both server and client are on the same subnet. Same issue I am encountering passing UPNP over VPN on OPT2 interface.

      Can someone please point me in the right direction to get this working?

      Thank you in advanced for any assistance in this matter.

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        Not knowing anything about your servers and what they do.. What is the purpose that you are trying to use UPNP?

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        G 1 Reply Last reply Reply Quote 0
        • G
          g405tsh311 @chpalmer
          last edited by g405tsh311

          @chpalmer The purpose for UPNP is to configure the client automatically. The server is a media server; however, irrelevant to the server function, the UPNP should be able to routed between the interfaces. As indicated previously, I have a computer directly connected to OPT1 interface and there is no indication of the UPNP call from the client passing to the LAN interface. I know the media server is configured properly since, if both, the client and server, are placed on the same subnet, meaning both on the same OPT1 interface, the client is able to discovered the UPNP connection to the media server. What actually needs to happen, is for the packets to pass between LAN to OPT1. The only remaining control is routing between the LAN interface and OPT1 interface.

          Thank you for your time.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by johnpoz

            Where did you get the idea that UPnP can be routed? It uses multicast 239.255.255.250

            What exactly are you wanting to do with UPnP - was the point of the question, because you might be able to get it work with either the igmp proxy or pimd. Depending the exact use case.

            But no its not going to just route across segments out of the box.

            Are you wanting your client to discover your DLNA server? If you give some specifics, we can discuss the options to get it to work.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            G chpalmerC 2 Replies Last reply Reply Quote 0
            • G
              g405tsh311 @johnpoz
              last edited by

              @johnpoz I understand that it is multicast and only addresses the computer on the same segment.
              While investigating the issue, in the pfsense documentation, only mentioned to enble UPNP & NAT-PMP which give the impression it will make UPNP work in a crossed inter face, this feature has been enabled but still no go. On the same note, UPNP & NAT-PMP is not needed if both systems are on the same segment sine I tested the connection with UPNP & NAT-PMP disable and I was able to discover the server from the client, again, as long as the client was in the same segment. Meaning, it defeat the purpose of this feature if it does not allow multicast passthrough between interfaces. Dosen't DLNA still depends on UPNP to discover devices?

              Answering your question, the idea is to discover DLNA and pass streaming to clients in the other segment of the network. Basically, if I can get UPNP to passthrough I think I can get DLNA to communicate with the other devices.

              Thank you in advance for your assistance.

              G 1 Reply Last reply Reply Quote 0
              • G
                g405tsh311 @g405tsh311
                last edited by

                Anyone that can provide some assistance on this issue?
                Could be possible that this is a bug in the pfsense?
                Any advice or recommendations trying to fix this issue?

                Thank you in advance.

                1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer @johnpoz
                  last edited by chpalmer

                  @johnpoz said in UPNP no routed between LAN and OPT1 interfaces.:

                  It uses multicast 239.255.255.250

                  g405tsh311 Read this.

                  https://forum.netgate.com/topic/139218/sonos-speakers-and-applications-on-different-subnets-vlan-s

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    I hope you were not directing that at me, but more quoting what I had already stated for the OP... I know exactly how it works ;) which was the reason for my posts in the first place - hehehe

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    chpalmerC 1 Reply Last reply Reply Quote 0
                    • chpalmerC
                      chpalmer @johnpoz
                      last edited by

                      @johnpoz said in UPNP no routed between LAN and OPT1 interfaces.:

                      I hope you were not directing that at me,

                      Nope.. I added the OP's name above. Originally intended to but brain shifted out of gear.. ✌

                      Triggering snowflakes one by one..
                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                      1 Reply Last reply Reply Quote 1
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        hehehe - yeah thats is what I figured ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.