Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port forward plex

    Scheduled Pinned Locked Moved Firewalling
    25 Posts 4 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MoonKnight
      last edited by

      @johnpoz
      I'm just curious, in you firewall rules, WAN.You have one rule at the bottom. You call it "Clean Block" Do you like to share the settings you have inside that rule?

      Thanks in advance!

      --- 24.11 ---
      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
      Kingston DDR4 2666MHz 16GB ECC
      2 x HyperX Fury SSD 120GB (ZFS-mirror)
      2 x Intel i210 (ports)
      4 x Intel i350 (ports)

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Its just there so I only log SYN… I don't care to see the UDP noise and any sort of out of state block.  So I turn off logging of the default block, and then only log SYN packets..

        Just set the SYN tcp flag is all in the advanced option.. This removes all the nonsense UDP noise and out of state nonsense that really don't care to see... But I am curious to what is the common ports being hit.. 3389, 22, 23, 1433, you know the typical ones.  But for example when that worm on the Mikrotik botnet was becoming popular saw a lot of port 8291 which was interesting..

        Still see that 8291 now and thing - just looked saw a hit back on 15th ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • M
          MoonKnight
          last edited by

          @johnpoz:

          Its just there so I only log SYN… I don't care to see the UDP noise and any sort of out of state block.  So I turn off logging of the default block, and then only log SYN packets..

          Just set the SYN tcp flag is all in the advanced option.. This removes all the nonsense UDP noise and out of state nonsense that really don't care to see... But I am curious to what is the common ports being hit.. 3389, 22, 23, 1433, you know the typical ones.  But for example when that worm on the Mikrotik botnet was becoming popular saw a lot of port 8291 which was interesting..

          Still see that 8291 now and thing - just looked saw a hit back on 15th ;)

          Thank you very much. I didn't think about this. Great idea to show if some shit is going on and more easy to read, instead of using "Log firewall default blocks"(to much noise) Yeah, i can see some of the ports you mentioned now in my log  :o :)

          Little bit off topic, sorry :)

          --- 24.11 ---
          Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
          Kingston DDR4 2666MHz 16GB ECC
          2 x HyperX Fury SSD 120GB (ZFS-mirror)
          2 x Intel i210 (ports)
          4 x Intel i350 (ports)

          1 Reply Last reply Reply Quote 0
          • S
            sakn1954
            last edited by

            I want to thank you very much, after all the headaches it was something stupid on my end. I decided to log into my freenas which runs my customplugin server, and there it was the plex plugin was off. Could not turn it on, so I rebooted and the plex plugin strted again and now everything is working. Thank you for all your help in this matter. I now a little more on port forwards,and firewall rules thanks to you.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              And don't forget you removed the any any rule that basically opened up your web gui to the world - so anyone on the planet might of guessed your pfsense username and password or sshed to it, etc. etc..

              Why did you create the any any rule on your wan?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.