Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Only Some of my Port Forwards work ?

    Scheduled Pinned Locked Moved Firewalling
    43 Posts 3 Posters 5.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by

      Are you providing a VOIP server locally?

      If the phone is local and the VOIP server remote you shouldn't need any sort of port forwards, I have a VOIP phone local and don't have any port forwards.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      C 1 Reply Last reply Reply Quote 0
      • C
        Cire3 @NogBadTheBad
        last edited by Cire3

        @nogbadthebad From my understanding the phone server is on site (Some Panasonic System) and the phone is off site (Cell Phone). Backwards in my opinion, but I believe they want to have a business phone in another location. I would use a server off site, not sure what he was sold or why.

        This port forward is squeezing my brain though.

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @Cire3
          last edited by NogBadTheBad

          @cire3 Try killing the firewall states.

          Diagnostics -> States -> Reset States

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          C 1 Reply Last reply Reply Quote 0
          • C
            Cire3 @NogBadTheBad
            last edited by

            @nogbadthebad Yea, just tried that a little bit ago. Same issue.

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @Cire3
              last edited by

              @cire3

              Those rules aren't disabled are they, there is a mini square in the tick box ?

              I don't use that colour scheme.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              C 1 Reply Last reply Reply Quote 0
              • C
                Cire3 @NogBadTheBad
                last edited by

                @nogbadthebad 9300 RUle.PNG

                My 9300 rule that auto populated when setting up NAT Port Forward

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @Cire3
                  last edited by NogBadTheBad

                  @cire3 I'd start doing a packet capture on the WAN interface to see if the packets are hitting the WAN interface, maybe the ISP is blocking some of the ports.

                  Also I was talking about the NAT rule with the mini square not the firewall rule.

                  Screenshot 2021-06-21 at 19.59.37.png

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  C 1 Reply Last reply Reply Quote 0
                  • C
                    Cire3 @NogBadTheBad
                    last edited by

                    @nogbadthebad said in Only Some of my Port Forwards work ?:

                    packet capture on the WAN

                    Sorry, thought you wanted rule, as I already posted the NAT Forward rules. My bad. However I double checked.

                    I'm connected over VPN, and know enough to be dangerous...lol Any way I can packet capture on the WAN remote ? Never had to do this.

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @Cire3
                      last edited by

                      @cire3 yup have a look at the diagnostics section.

                      You can download the packet capture from the page and view in wireshark.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      C 1 Reply Last reply Reply Quote 0
                      • C
                        Cire3 @NogBadTheBad
                        last edited by

                        @nogbadthebad Just seen it after I asked the question. Way cool. Downloading now after trying to check port.

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          Cire3 @Cire3
                          last edited by

                          @cire3 Host address being my Static WAN ? And should I use a port or just capture?

                          C 1 Reply Last reply Reply Quote 0
                          • C
                            Cire3 @Cire3
                            last edited by

                            @cire3 Packate Capture 9300.PNG

                            And this from PFSense :

                            15:25:00.282522 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                            15:25:01.278833 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                            15:25:01.283582 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                            15:25:02.282636 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                            15:25:02.284759 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                            15:25:03.282818 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                            15:25:56.035819 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                            15:25:57.034127 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                            15:25:57.036750 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                            15:25:58.034059 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                            15:25:58.038290 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                            15:25:59.038237 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                            15:26:00.276783 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                            15:26:01.274091 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                            15:26:01.277837 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                            15:26:02.273897 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                            15:26:02.278893 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0
                            15:26:03.277951 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0

                            NogBadTheBadN 1 Reply Last reply Reply Quote 0
                            • NogBadTheBadN
                              NogBadTheBad @Cire3
                              last edited by

                              @cire3 OK so it looks like 9300 is hitting the WAN interface.

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              C 1 Reply Last reply Reply Quote 0
                              • C
                                Cire3 @NogBadTheBad
                                last edited by

                                @nogbadthebad Yea, It would have been great to blame Comcast. Not today I guess...lol

                                C 1 Reply Last reply Reply Quote 0
                                • C
                                  Cire3 @Cire3
                                  last edited by

                                  @cire3 Firewall Rules WAN.PNG

                                  Figured I would post in case something didn't look right

                                  C NogBadTheBadN 2 Replies Last reply Reply Quote 0
                                  • C
                                    Cire3 @Cire3
                                    last edited by

                                    @cire3 States.PNG

                                    This is what's back in states

                                    1 Reply Last reply Reply Quote 0
                                    • NogBadTheBadN
                                      NogBadTheBad @Cire3
                                      last edited by NogBadTheBad

                                      @cire3 Rules are read from the top down, I suggest you have a read:-

                                      https://docs.netgate.com/pfsense/en/latest/firewall/rule-list-intro.html

                                      Everything TCP will hit the 3rd rule down.

                                      Andy

                                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                      C 2 Replies Last reply Reply Quote 0
                                      • C
                                        Cire3 @NogBadTheBad
                                        last edited by

                                        @nogbadthebad Reset States again, waiting for it to boot back up and VPN in

                                        1 Reply Last reply Reply Quote 0
                                        • C
                                          Cire3 @NogBadTheBad
                                          last edited by

                                          @nogbadthebad UDP to TCP/UDP to TCP. No change

                                          NogBadTheBadN 1 Reply Last reply Reply Quote 0
                                          • NogBadTheBadN
                                            NogBadTheBad @Cire3
                                            last edited by

                                            @cire3 If you still have that 3rd rule you need to delete it, it won't hit your NAT rule.

                                            Its very dangerous what you've done with that rule and if you havent noticed all your TCP traffic is hitting it.

                                            Andy

                                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                            C 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.