Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT'ing external port on VIP to internet LAN IP

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      berniecnyc
      last edited by

      so i have a WAN connection with 5 static IPs

      98.1o9.113.99 is the IP of the WAN interface itself and 100, 101, 102 are addresses I've added as IP aliases to my pf sense box.

      The end goal here is to have traffic that hits VIP 09.1o9.113.100 on TCP 80 to be NAT'd to internal host 10.84.5.13

      I tried adding a NAT rule for this without any success.  I then tried putting a FW rule on top of that without any success.  I'm a little stumped.

      I've enclosed screen shots of my configs

      thanks in advance for looking!!
      VIP.png
      VIP.png_thumb
      port_fwd.png
      port_fwd.png_thumb
      fw_rule.png
      fw_rule.png_thumb

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        The NAT looks ok.  Your firewall rule image is incomplete.  Post a screenshot of the entire firewall rule please from the WAN rules screen.  Sanitize anything sensitive.

        1 Reply Last reply Reply Quote 0
        • B
          berniecnyc
          last edited by

          here is the lower half of the fw rule screen -  display resolution wont let me screen shot the whole thing at once.

          fw_rule.png
          fw_rule.png_thumb

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Don't set source ports in your Port Forwards.

            You had to click advanced then ignore this:

            Specify the source port or port range for this rule. This is usually random and almost never equal to the destination port range (and should usually be 'any'). The 'to' field may be left empty if only filtering a single port.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • B
              berniecnyc
              last edited by

              @Derelict:

              Don't set source ports in your Port Forwards.

              You had to click advanced then ignore this:

              Specify the source port or port range for this rule. This is usually random and almost never equal to the destination port range (and should usually be 'any'). The 'to' field may be left empty if only filtering a single port.

              I'm a little confused by your post. 
              I don't have any source port specified as the screen shots show - i only have destination specified.  Am I misunderstanding what you are trying to tell me?

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                https://forum.pfsense.org/index.php?action=dlattach;topic=120148.0;attach=89431;image

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM
                  last edited by

                  Don't set source ports in your Port Forwards.

                  D'oh, good catch.  I didn't notice that at all.

                  1 Reply Last reply Reply Quote 0
                  • K
                    kpa
                    last edited by

                    You don't set source port requirements in the NAT rules. What the rule is now saying is "Perform the RDR only if the source port in the incoming packet is 80" (and of course the other requirements have to be met as well). This is never going to be true for regular HTTP traffic arriving to your end, the source port is going to be a randomly chosen port from range 1024:65535.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.