Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense 2.5.0.a.20201127.0650 NAT Issues

    Scheduled Pinned Locked Moved NAT
    22 Posts 4 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Replied on PM. But new need a pcap on the tier1 WAN while connecting via the tier2 WANB to verify replies are being sent that way rather than dropped for some reason.

      You gateway groups are not being populated in the ruleset. The only reason that should ever happen normally is if you have not set Skip rules when gateway is down and all the gateways were down. Which clearly isn't the case here.
      You are not policy routing anything via those so it won't affect anything directly but could indicate the gateways have some odd setting.

      Steve

      dragoangelD 2 Replies Last reply Reply Quote 0
      • dragoangelD
        dragoangel @stephenw10
        last edited by

        @stephenw10 said in pfSense 2.5.0.a.20201127.0650 NAT Issues:

        You gateway groups are not being populated in the ruleset. The only reason that should ever happen normally is if you have not set Skip rules when gateway is down and all the gateways were down. Which clearly isn't the case here.

        Yes, this isn't the case. I not see any bit of traffic when dump WAN TIER1 while trying connect to WAN TIER2. Can it be due promiscuous mode isn't enabled? I doesn't think so.

        Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
        Unifi AP-AC-LR with EAP RADIUS, US-24

        dragoangelD 1 Reply Last reply Reply Quote 0
        • dragoangelD
          dragoangel @dragoangel
          last edited by

          @stephenw10 send pfSense status report to your email

          Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
          Unifi AP-AC-LR with EAP RADIUS, US-24

          1 Reply Last reply Reply Quote 0
          • dragoangelD
            dragoangel @stephenw10
            last edited by

            Hi, @stephenw10 I done full reinstall from scratch to 2.4.5_p1 on ssd and updated to 2.5.0.a.20201127.0650 and restored from backup - still same issue with:

            GWWANGROUP = "  "
            GWWANGROUP6 = "  "
            

            I also found in logs:

            Jan 5 00:16:21 	php-fpm 	97323 	/rc.filter_configure_sync: An error occurred while trying to find the interface got `MyMainIPv6GWIP`. The rule has not been added.
            Jan 5 00:16:21 	php-fpm 	97323 	/rc.filter_configure_sync: An error occurred while trying to find the interface got `MyMainIPv4GWIP`. The rule has not been added. 
            

            Maybe this root case why I have this?

            Also want to note: when I restore from backup - if I used console\terminal it always "merges" in strange way my xg7100u switch configs and break everything, due to this reinstall takes for me crazy long and was successful only on second time. It will be cool if pfsense on terminal also ask about preserving switch conf or not.

            Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
            Unifi AP-AC-LR with EAP RADIUS, US-24

            dragoangelD 1 Reply Last reply Reply Quote 0
            • dragoangelD
              dragoangel @dragoangel
              last edited by

              @stephenw10 can you please help with this issue? It still in place. Also I doesn't receive any updates on my development 2.5 pfsense even that comes on 2.4.5_p1 stable (on another xg7100u).

              Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
              Unifi AP-AC-LR with EAP RADIUS, US-24

              1 Reply Last reply Reply Quote 1
              • S
                saeed
                last edited by

                Hi,
                after upgrading to 2.5.1 my port forwards only works for active wan. is it related to this bug?
                any solution?

                dragoangelD 1 Reply Last reply Reply Quote 0
                • dragoangelD
                  dragoangel @saeed
                  last edited by

                  @saeed you need update to latest version and it will fix nat, but not NPt for ipv6.

                  Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                  Unifi AP-AC-LR with EAP RADIUS, US-24

                  S 2 Replies Last reply Reply Quote 0
                  • S
                    saeed @dragoangel
                    last edited by

                    @dragoangel said in pfSense 2.5.0.a.20201127.0650 NAT Issues:

                    you need update to latest version and it will fix nat, but not NPt for ipv6.

                    it's a production server and already updated to 2.5.1
                    you mean update to latest development snapshot?

                    1 Reply Last reply Reply Quote 0
                    • S
                      saeed @dragoangel
                      last edited by

                      @dragoangel
                      https://redmine.pfsense.org/issues/11805

                      dragoangelD 1 Reply Last reply Reply Quote 0
                      • dragoangelD
                        dragoangel @saeed
                        last edited by

                        @saeed I have pfsense plus so for me firmware is 21.02.2. For CE, yes - it still unresolved.

                        Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                        Unifi AP-AC-LR with EAP RADIUS, US-24

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Despite extensive testing before release it's still possible to hit this in 2.5.1 CE but not as far as we know in 21.02.2 (Plus). Though it's unclear what the difference there is.
                          https://redmine.pfsense.org/issues/11805

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.