Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Only Some of my Port Forwards work ?

    Firewalling
    3
    43
    5.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cire3
      last edited by Cire3

      Starting to define the definition of insanity.

      I have a phone system just installed and was given a list of ports that need forwarded to the phone system. However only half of them work ? I have deleted them, re-entered them, and they are identical to the working ones.

      List of ports needed :

      9300 - 9300 to 10.10.1.25 Closed
      24493 to 2728 to 10.10.1.25 Open
      16000 -16511 to 10.10.1.16 Closed
      44443 to 443 to 10.10.1.25 Open

      The conversion ports for whatever reason work, but the port to port do not ?

      PFSense 2.5.1 (Just upgraded it and made no difference.

      Where to go from here ?

      1 Reply Last reply Reply Quote 0
      • C
        Cire3
        last edited by

        working.PNG

        1 Reply Last reply Reply Quote 0
        • C
          Cire3
          last edited by

          Not Working.PNG

          This one is not working.

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            Are you providing a VOIP server locally?

            If the phone is local and the VOIP server remote you shouldn't need any sort of port forwards, I have a VOIP phone local and don't have any port forwards.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            C 1 Reply Last reply Reply Quote 0
            • C
              Cire3 @NogBadTheBad
              last edited by Cire3

              @nogbadthebad From my understanding the phone server is on site (Some Panasonic System) and the phone is off site (Cell Phone). Backwards in my opinion, but I believe they want to have a business phone in another location. I would use a server off site, not sure what he was sold or why.

              This port forward is squeezing my brain though.

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @Cire3
                last edited by NogBadTheBad

                @cire3 Try killing the firewall states.

                Diagnostics -> States -> Reset States

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                C 1 Reply Last reply Reply Quote 0
                • C
                  Cire3 @NogBadTheBad
                  last edited by

                  @nogbadthebad Yea, just tried that a little bit ago. Same issue.

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad @Cire3
                    last edited by

                    @cire3

                    Those rules aren't disabled are they, there is a mini square in the tick box ?

                    I don't use that colour scheme.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      Cire3 @NogBadTheBad
                      last edited by

                      @nogbadthebad 9300 RUle.PNG

                      My 9300 rule that auto populated when setting up NAT Port Forward

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @Cire3
                        last edited by NogBadTheBad

                        @cire3 I'd start doing a packet capture on the WAN interface to see if the packets are hitting the WAN interface, maybe the ISP is blocking some of the ports.

                        Also I was talking about the NAT rule with the mini square not the firewall rule.

                        Screenshot 2021-06-21 at 19.59.37.png

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          Cire3 @NogBadTheBad
                          last edited by

                          @nogbadthebad said in Only Some of my Port Forwards work ?:

                          packet capture on the WAN

                          Sorry, thought you wanted rule, as I already posted the NAT Forward rules. My bad. However I double checked.

                          I'm connected over VPN, and know enough to be dangerous...lol Any way I can packet capture on the WAN remote ? Never had to do this.

                          NogBadTheBadN 1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN
                            NogBadTheBad @Cire3
                            last edited by

                            @cire3 yup have a look at the diagnostics section.

                            You can download the packet capture from the page and view in wireshark.

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            C 1 Reply Last reply Reply Quote 0
                            • C
                              Cire3 @NogBadTheBad
                              last edited by

                              @nogbadthebad Just seen it after I asked the question. Way cool. Downloading now after trying to check port.

                              C 1 Reply Last reply Reply Quote 0
                              • C
                                Cire3 @Cire3
                                last edited by

                                @cire3 Host address being my Static WAN ? And should I use a port or just capture?

                                C 1 Reply Last reply Reply Quote 0
                                • C
                                  Cire3 @Cire3
                                  last edited by

                                  @cire3 Packate Capture 9300.PNG

                                  And this from PFSense :

                                  15:25:00.282522 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                                  15:25:01.278833 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                                  15:25:01.283582 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                                  15:25:02.282636 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                                  15:25:02.284759 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                                  15:25:03.282818 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                                  15:25:56.035819 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                                  15:25:57.034127 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                                  15:25:57.036750 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                                  15:25:58.034059 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                                  15:25:58.038290 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                                  15:25:59.038237 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                                  15:26:00.276783 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                                  15:26:01.274091 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                                  15:26:01.277837 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                                  15:26:02.273897 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                                  15:26:02.278893 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0
                                  15:26:03.277951 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0

                                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                                  • NogBadTheBadN
                                    NogBadTheBad @Cire3
                                    last edited by

                                    @cire3 OK so it looks like 9300 is hitting the WAN interface.

                                    Andy

                                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                    C 1 Reply Last reply Reply Quote 0
                                    • C
                                      Cire3 @NogBadTheBad
                                      last edited by

                                      @nogbadthebad Yea, It would have been great to blame Comcast. Not today I guess...lol

                                      C 1 Reply Last reply Reply Quote 0
                                      • C
                                        Cire3 @Cire3
                                        last edited by

                                        @cire3 Firewall Rules WAN.PNG

                                        Figured I would post in case something didn't look right

                                        C NogBadTheBadN 2 Replies Last reply Reply Quote 0
                                        • C
                                          Cire3 @Cire3
                                          last edited by

                                          @cire3 States.PNG

                                          This is what's back in states

                                          1 Reply Last reply Reply Quote 0
                                          • NogBadTheBadN
                                            NogBadTheBad @Cire3
                                            last edited by NogBadTheBad

                                            @cire3 Rules are read from the top down, I suggest you have a read:-

                                            https://docs.netgate.com/pfsense/en/latest/firewall/rule-list-intro.html

                                            Everything TCP will hit the 3rd rule down.

                                            Andy

                                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                            C 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.