Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port Fowards are not working

    Scheduled Pinned Locked Moved NAT
    9 Posts 3 Posters 847 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      Zm1868179
      last edited by

      I have a PC Engines APU2 that is running PFsense 2.3.5 and i am unable to get port forwarding working at all.  I currently have 1 NAT port forward working but all others i Add are not working at all. I noticed the issue when i attempted to setup and forward port 80 to my web server which work internally but externally i cant access it I even attempted to forward Remote desktop and that didn't work either. I have firewall optimization set on Conservative, I do have Vlans set up and under rules all vlans can talk to each other
      Under NAT  for my port forward for RDP I have:

      Interface WAN
      Destination Port MS RDP to MS RDP
      Redirected IP 10.10.2.2
      Redirected Port MS RDP

      For the Port 80 I have
      Interface WAN
      Destination Port HTTP to HTTP
      Redirected IP 10.10.2.7
      Redirected Port HTTP

      Internally if i just visit 10.10.2.7 by IP address i get the default IIS page which is what should happen when i visit my External IP address but i get nothing at all. Firewall logs when i search for my cell phones external IP address shows its being blocked by the default Deny Rule

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        So you created a  port forward, you can not just create your wan rule..

        Please post up screenshots vs what you think you did.

        Also forwarding Remote desktop is a HUGE freaking mistake!!!

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • Z
          Zm1868179
          last edited by

          Yea here is a screen shot of the Rules and the Nat and the deny from the firewall for the http request from my cell phone as a test
          I know RDP is a bad idea it just something i had on my phone just to test to see if its anything i forward or just web traffic

          Capture.PNG
          Capture.PNG_thumb
          Capture2.PNG
          Capture2.PNG_thumb
          Capture3.PNG
          Capture3.PNG_thumb
          Capture4.PNG
          Capture4.PNG_thumb
          Capture5.PNG
          Capture5.PNG_thumb

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Your forwarding SQL as well - Wow talk about wanting to get tagged..

            Did you actually hit apply did the rules reload.. I don't see any hits on that rule at all.  On the wan rule.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • Z
              Zm1868179
              last edited by

              Sorry for the long reply lost connection but yes the rule is applied but no matter what i have tried the sql is the only thing that seems to come in. I not using it for sql access i wrote an application that listens on those ports to grab sql backups and store them on a another device than what the application sits on

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                And the bots of the world are going to be tagging that port every few minutes ;)

                So it shows in your log when those rules were loaded…

                Is that IP actually your WAN address?  Or is it some other vip?  Look in your log for when your rules reloaded.. Go in and redo your forward and check your logs...

                portforward.png
                portforward.png_thumb

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • Z
                  Zm1868179
                  last edited by

                  Yea its one of my static IP Addresses I have a few i just changed to a different Static IP address deleted the Nat port forward and remade it and had it just point to the internal web page on a switch i have and again same thing unable to access it externally

                  So i installed PFsense Version 2.3.1 on the same type of hardware an PC Engines APU2 and setup port forwards by going under NAT and setting up rdp and http just to test and it works but as soon as i put the APU2 with PFSense 2.3.5 in place setup exactly the same it doesn't work

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    Dude - if you have multiple IPs you have to create a VIP for the IP you want to use… And then you have to use that VIP as your nat..

                    Nice if you would of mentioned you had a /? with static IPs on your wan, etc..

                    Did you create your VIPs?  Here I created a dummy vip... I then used that as the dest in the port forward destination.

                    vipportforward.png
                    vipportforward.png_thumb

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Note you don't strictly NEED a VIP if the traffic for those addresses is routed to the WAN interface. All that matters is the traffic arrives. If so, NAT will happen.

                      If it is an address in the WAN subnet (or some silly, unrouted, secondary WAN subnet) then you must have something that will respond to ARP from upstream in place on WAN, meaning one of the VIP types except Other.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.