• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Port Forwarding with Comcast Internet

Scheduled Pinned Locked Moved Firewalling
9 Posts 4 Posters 2.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    crowdx44
    last edited by Apr 20, 2017, 12:07 AM

    Hi all,
    so I installed pfsense last weekend, got my wifi and internet working great, love the many features. Then I hit a snag, I have a DVR setup running security cameras which I port forward for external network access. This works great with my ASUS RT-AC68U router which uses their DNS forwarding service and allows me to forward the port that way.
    With pfsense I setup the port forwarding and checked canyouseeme.org and it errors out. I also tried my app on my phone using the ip address I have from Comcast, still no joy.
    What could the issue be? I have applied settings once the NAT rule is setup and it shows in the Firewall rules page. Could Comcast be blocking direct ip port forwarding? I would think it would be no different than what ASUS DNS service does?
    Thoughts? I have searched online but I am not seeing anyone else with this issue, I have looked at a dozen Youtube videos and they all show I am doing everything standard. Is there some undocumented step?
    Help!!
    Patrick

    1 Reply Last reply Reply Quote 0
    • I
      isolatedvirus
      last edited by Apr 20, 2017, 5:47 AM

      Depends on the port being forwarded. If you're on a residential connection Comcast will filter certain ports.

      First, check the IP of your DVR. Next make sure your port forward is targeting the correct IP. After that, verify your firewall rule says its allowing access to the IP of the DVR.

      If possible, provide some screenshots of your relevant rules to help with assisting you.

      Personally I'd recommend against a wide open DVR, as anyone performing scans could find it. (Scans are constantly happening.) If it were me I'd only allow access to that through a VPN. Sorry for the soapbox but I just wanted to make sure you're aware of the risks involved.

      1 Reply Last reply Reply Quote 0
      • J
        JKnott
        last edited by Apr 20, 2017, 2:18 PM

        ^^^^
        Given that it works with the Asus router, I doubt the problem is caused by Comcast.  I agree, however, that a VPN or other secure connection be used.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator
          last edited by Apr 20, 2017, 7:03 PM Apr 20, 2017, 3:58 PM

          "I have a DVR setup running security cameras which I port forward for external network access."

          This is a bad idea to be honest.  Have you not seen all the news about camera's with backdoors, etc.  If you want to view your video stream while away you really should vpn in verses opening up such stuff to the public internet.

          I would hope you have it locked down to specific source IPs.

          I would verify the traffic is actually hitting your pfsense.  It has your public IP on its wan right, your not behind a comcast gateway device that does not.  And your only using a modem?  I have comcast and have zero issues with port forwarding.

          Go to canyouseeme.org and send some test traffic to your tcp ports you have forwarded.. Do you see the traffic on pfsense wan?  Simple enough to check with packet capture under diagnostics.

          Follow the troubleshooting guide to find out where you went wrong.
          https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

          Port forwarding with pfsense is really just click click..  Easier and more robust any off the shelf soho router that is for damn sure..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • C
            crowdx44
            last edited by Apr 20, 2017, 6:48 PM

            So the reason I wanted to use pfsense was exactly that, I want to put my vpn connection on the router. With the ASUS router when I put the VPN on the router my speeds drop to 10mbps vs the 180mbps I normally get with the same software vpn (Nordvpn) .
            I will go test again, and see if I can find the issue. I have never had an issue before with port forwarding and I also read the troubleshooting doc which confirms everything I have done.

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by Apr 20, 2017, 7:05 PM

              "router my speeds drop to 10mbps vs the 180mbps I normally get with the same software vpn (Nordvpn) ."

              Huh??  nordvpn is a vpn service which would be for your connection to the internet, not for vpn  into your system..

              What is your internet speeds down/up?  And what is the speeds your connecting to your vpn running on your router from.. Your going to be limited to your update speed, etc.  How are you measuring speed?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • C
                crowdx44
                last edited by Apr 20, 2017, 7:25 PM

                I have Comcast 150/10 , when I use the NordVPN client on a local node I get pretty close to the speeds I get connecting direct. When I setup open vpn on the ASUS router so that everyone on the network can connect online via the vpn, the speed drop to about 10% of the provider speeds.
                I have read that regular routers cannot process the vpn fast enough and this causes the slow speeds. So I decided to the pfsense on an i3 2.9ghz machine I had lying around.
                I presume from your comments, I don't need a service provider like Nordvpn to vpn directly to a machine?

                1 Reply Last reply Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator
                  last edited by Apr 21, 2017, 5:08 AM

                  no some vpn service out on the internet is not how you would vpn into your network to access stuff while your remote.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • I
                    isolatedvirus
                    last edited by Apr 21, 2017, 6:23 AM

                    While it IS possible to set up port forwarding through a VPN and do dynamic DNS to resolve a domain that you know to target, it would be cheaper and easier if you just setup openvpn on your pfsense box as a server instead of as a client. If you're using nordvpn for other reasons such as privacy, that's a different setup entirely.

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received