<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[UPnP &amp; Static NAT but still NAT: Moderate CoD BO2?]]></title><description><![CDATA[<p dir="auto">I've set the machine I use Steam on to a static IP, and given it and only it UPnP:</p>
<p dir="auto">Enable UPnP<br />
Allow Port Mapping<br />
External: WAN<br />
Interface: Guest LAN<br />
Traffic Shaping: qGames<br />
Log Packets<br />
Uptime<br />
Default Deny<br />
ACL Entry: allow 1024-65535 192.168.16.7 1024-65535 (I initially tried 1-65535 on both, but it was still Moderate)</p>
<p dir="auto">Outbound NAT Rule:</p>
<p dir="auto">WAN<br />
TCP/UDP<br />
SOURCE: Network, 192.168.16.7/32<br />
Destination: any 3074:3076<br />
Translation: Interface Address<br />
Static Port</p>
<p dir="auto">I flush the states, and restart the game and still at NAT: Moderate</p>
<p dir="auto">What else is there to do?</p>
]]></description><link>https://forum.netgate.com/topic/111935/upnp-static-nat-but-still-nat-moderate-cod-bo2</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 12:54:18 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/111935.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Feb 2017 19:59:37 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to UPnP &amp; Static NAT but still NAT: Moderate CoD BO2? on Tue, 21 Feb 2017 23:32:11 GMT]]></title><description><![CDATA[<p dir="auto">Probably be good to post some screen shots of your config.</p>
<p dir="auto">Step 1. DHCP Static Mapping<br />
Step 2. Outbound NAT rule &amp; mapping order (put it at the top)<br />
Step 3. NAT Port forwards<br />
Step 4. UPnP Config<br />
Step 5. Firewall rules</p>
<p dir="auto">At a minimum, your firewall rules should allow traffic to port 1900 for the uPnP SSDP discovery broadcast, and to port 2189 to talk to the miniupnpd server</p>
<p dir="auto">Also, to diagnose this, you can either do a Diagnostics - Packet Capture on your PC and comb through the capture to map out your traffic OR setup a Floating Match rule to log all traffic in &amp; out of your PC into the firewall log.  Then correlate those to WAN block/pass events.</p>
]]></description><link>https://forum.netgate.com/post/681561</link><guid isPermaLink="true">https://forum.netgate.com/post/681561</guid><dc:creator><![CDATA[Double K]]></dc:creator><pubDate>Tue, 21 Feb 2017 23:32:11 GMT</pubDate></item><item><title><![CDATA[Reply to UPnP &amp; Static NAT but still NAT: Moderate CoD BO2? on Tue, 21 Feb 2017 22:37:24 GMT]]></title><description><![CDATA[<p dir="auto">Still Moderate, however, on Status / UPnP there is nothing.</p>
<p dir="auto">What am I doing wrong there?</p>
]]></description><link>https://forum.netgate.com/post/681548</link><guid isPermaLink="true">https://forum.netgate.com/post/681548</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Tue, 21 Feb 2017 22:37:24 GMT</pubDate></item><item><title><![CDATA[Reply to UPnP &amp; Static NAT but still NAT: Moderate CoD BO2? on Tue, 21 Feb 2017 22:19:49 GMT]]></title><description><![CDATA[<p dir="auto">Thanks, I see one from 3075 to 3074 getting blocked, assume that's no different. So inbound port forward to 3074 on the PC and a firewall rule? I'll try that!</p>
]]></description><link>https://forum.netgate.com/post/681541</link><guid isPermaLink="true">https://forum.netgate.com/post/681541</guid><dc:creator><![CDATA[pfBasic]]></dc:creator><pubDate>Tue, 21 Feb 2017 22:19:49 GMT</pubDate></item><item><title><![CDATA[Reply to UPnP &amp; Static NAT but still NAT: Moderate CoD BO2? on Tue, 21 Feb 2017 22:04:06 GMT]]></title><description><![CDATA[<p dir="auto">This sounds eerily similar to this topic: https://forum.pfsense.org/index.php?topic=124988.0</p>
<p dir="auto">What port(s) is your PC getting in Status/UPnP when running CoD?  3074?</p>
<p dir="auto">When you first start CoD - do you see 1 entry in your firewall log on the WAN interface with a Block of an unsolicited inbound packet from a demonware server on port 3075 to your public IP address on port 3076?  If so, add an inbound port forward for 3076 to your PC (along with the associated firewall rule).</p>
<p dir="auto">Also, don't limit your outbound nat rule to only port 3074:3076 on the destination…leave that port field blank.</p>
]]></description><link>https://forum.netgate.com/post/681536</link><guid isPermaLink="true">https://forum.netgate.com/post/681536</guid><dc:creator><![CDATA[Double K]]></dc:creator><pubDate>Tue, 21 Feb 2017 22:04:06 GMT</pubDate></item></channel></rss>