• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pass specific IP through to LAN, port forwarding, firewall rules

Scheduled Pinned Locked Moved General pfSense Questions
24 Posts 2 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    AKJim
    last edited by Feb 3, 2019, 2:57 PM

    Hello, new Netgate appliance, new to pfSense and just getting this new device configured. Fairly smooth, except for the following: I have a Synology DS in Chugiak which backs up daily to a remote Synology DS in Blacksburg. I am now placing the Netgate appliance between the cable modem and my router in Blacksburg. I must be missing something in configuring the port forwarding and firewall rule on the Netgate. I want to allow all traffic from the specific IP address hosting the Chugiak DS through the netgate to the Blacksburg DS, all ports. I have read through the pfSense documentation regarding both port forwarding and firewall rules, plus searched the forums. I have deleted and properly recreated port forwarding rules, rebooted the netgate. What am I missing? Thank you for your help!! Screenshots of my current configuration are attached: 0_1549205786283_pfSense problem_1.png 0_1549205800636_pfSense problem_2.png 0_1549205807936_pfSense problem_3.png

    K 1 Reply Last reply Feb 3, 2019, 3:32 PM Reply Quote 0
    • K
      Konstanti @AKJim
      last edited by Konstanti Feb 3, 2019, 3:38 PM Feb 3, 2019, 3:32 PM

      @akjim
      Hey
      which service Synology performs the backup?
      Hyper Backup ?

      A 1 Reply Last reply Feb 3, 2019, 3:39 PM Reply Quote 0
      • A
        AKJim @Konstanti
        last edited by Feb 3, 2019, 3:39 PM

        @konstanti said in Pass specific IP through to LAN, port forwarding, firewall rules:

        @akjim
        Hey
        which service Synology performs the backup?

        Synology's HyperBackup

        K 2 Replies Last reply Feb 3, 2019, 3:40 PM Reply Quote 0
        • K
          Konstanti @AKJim
          last edited by Feb 3, 2019, 3:40 PM

          @akjim

          Do not pay attention to the Russian language
          Everything is clear
          What ports do I need to forward for Hyper Backup
          What you're doing is wrong.

          0_1549208396314_c5a0753d-955d-456e-a6ac-f4414e015c93-image.png

          1 Reply Last reply Reply Quote 0
          • K
            Konstanti @AKJim
            last edited by Feb 3, 2019, 3:42 PM

            @akjim
            The first picture shows that pf is blocking tcp port 6281

            A 1 Reply Last reply Feb 3, 2019, 3:45 PM Reply Quote 0
            • A
              AKJim @Konstanti
              last edited by Feb 3, 2019, 3:45 PM

              @konstanti Yes, I know that. Hyperbackup is set up correctly. I just need to get the connection through the netgate to the Blacksburg DS. Without the netgate in the system everything works perfectly.

              K 1 Reply Last reply Feb 3, 2019, 3:46 PM Reply Quote 0
              • K
                Konstanti @AKJim
                last edited by Konstanti Feb 3, 2019, 3:52 PM Feb 3, 2019, 3:46 PM

                @akjim

                0_1549208759667_0047344d-1960-4d94-9d00-9abc14b8ca9d-image.png

                This way, the required ports are forwarded
                Everything else need to disable and remove
                https://www.netgate.com/docs/pfsense/nat/forwarding-ports-with-pfsense.html

                A 1 Reply Last reply Feb 3, 2019, 3:55 PM Reply Quote 0
                • A
                  AKJim @Konstanti
                  last edited by Feb 3, 2019, 3:55 PM

                  @konstanti OK, so a single port forwarding rule without a specified single host defined. No corresponding firewall rule is required?

                  K 1 Reply Last reply Feb 3, 2019, 3:59 PM Reply Quote 0
                  • K
                    Konstanti @AKJim
                    last edited by Konstanti Feb 3, 2019, 4:02 PM Feb 3, 2019, 3:59 PM

                    @akjim

                    0_1549209547187_9ac8b652-26f2-4d37-8166-e24bb1429378-image.png

                    pf will create the rule automatically
                    for example
                    0_1549209750534_2ae5df67-a3ae-4466-82ec-a32f58fd54df-image.png

                    0_1549209678147_1d526703-abac-4f10-963e-ffe07ed63848-image.png

                    1 Reply Last reply Reply Quote 0
                    • A
                      AKJim
                      last edited by Feb 3, 2019, 4:23 PM

                      Hmmm ..... it's still not going through. I'll delete the rule again, reboot the netgate and start fresh. I appreciate your help. Be back after the fresh start ....

                      K 1 Reply Last reply Feb 3, 2019, 4:29 PM Reply Quote 0
                      • K
                        Konstanti @AKJim
                        last edited by Konstanti Feb 3, 2019, 4:33 PM Feb 3, 2019, 4:29 PM

                        @akjim

                        We have to start over

                        1. remove and disable all that in the pictures ( this is wrong)
                        2. create port forwarding for 6281 (nat / port forwarding)
                        3. check that the rule on the wan interface also appeared
                        4. try to connect

                        how is port forwarding configured on the router ?

                        A 1 Reply Last reply Feb 3, 2019, 4:35 PM Reply Quote 0
                        • A
                          AKJim @Konstanti
                          last edited by Feb 3, 2019, 4:35 PM

                          @konstanti said in Pass specific IP through to LAN, port forwarding, firewall rules:

                          @akjim

                          We have to start over

                          1. remove and disable all that in the pictures ( this is wrong)
                          2. create port forwarding for 6281 (nat / port forwarding)
                          3. check that the rule on the wan interface also appeared
                          4. try to connect
                          1. Yes, I have removed all rules, then rebooted the device.
                          2. Yes, done
                          3. Yes: 0_1549211668263_8b4a3dc8-5d00-49f2-a971-88a7a04fc604-image.png
                          4. Still rejected by device firewall: 0_1549211712076_8168876b-5de1-4de2-9ab6-bc62b543250e-image.png
                          K A 2 Replies Last reply Feb 3, 2019, 4:37 PM Reply Quote 0
                          • K
                            Konstanti @AKJim
                            last edited by Feb 3, 2019, 4:37 PM

                            @akjim
                            show me the rules on the wan interface

                            A 1 Reply Last reply Feb 3, 2019, 4:39 PM Reply Quote 0
                            • A
                              AKJim @AKJim
                              last edited by Feb 3, 2019, 4:37 PM

                              @akjim Port forwarding on the router is good, this traffic is being stopped by the netgate appliance only. If I remove the netgate appliance (pfSense) then everything works correctly.

                              1 Reply Last reply Reply Quote 0
                              • A
                                AKJim @Konstanti
                                last edited by Feb 3, 2019, 4:39 PM

                                @konstanti said in Pass specific IP through to LAN, port forwarding, firewall rules:

                                @akjim
                                show me the rules on the wan interface

                                0_1549211955107_dab2a242-d591-44cc-90fc-30ee4689c97c-image.png
                                0_1549211972674_76e3ae0a-3923-4d6e-a30d-2976762b0c38-image.png
                                0_1549211990825_9ff718a1-4856-4990-999f-aec75f61d31b-image.png

                                K 2 Replies Last reply Feb 3, 2019, 4:41 PM Reply Quote 0
                                • K
                                  Konstanti @AKJim
                                  last edited by Feb 3, 2019, 4:41 PM

                                  @akjim
                                  this is not what we need

                                  i need
                                  /firewall/rules/wan

                                  A 1 Reply Last reply Feb 3, 2019, 4:54 PM Reply Quote 0
                                  • K
                                    Konstanti @AKJim
                                    last edited by Konstanti Feb 3, 2019, 4:47 PM Feb 3, 2019, 4:44 PM

                                    @akjim

                                    and I need a full log entry.
                                    to see what pf is blocking
                                    Status/System Logs/Firewall/Normal View
                                    where you will see :interface, source, destination, port, protocol

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      AKJim @Konstanti
                                      last edited by Feb 3, 2019, 4:54 PM

                                      @konstanti said in Pass specific IP through to LAN, port forwarding, firewall rules:

                                      @akjim
                                      this is not what we need

                                      i need
                                      /firewall/rules/wan

                                      1_1549212815787_pfSense problem 00002.png 0_1549212815787_pfSense problem 00001.png

                                      K 1 Reply Last reply Feb 3, 2019, 4:56 PM Reply Quote 0
                                      • K
                                        Konstanti @AKJim
                                        last edited by Konstanti Feb 3, 2019, 4:58 PM Feb 3, 2019, 4:56 PM

                                        @akjim

                                        here's what I need
                                        the picture with all the rules
                                        for example ,

                                        0_1549212994252_33e9ee16-3061-4362-be3d-15957cb12a15-image.png

                                        A 1 Reply Last reply Feb 3, 2019, 5:01 PM Reply Quote 0
                                        • A
                                          AKJim @Konstanti
                                          last edited by Feb 3, 2019, 5:01 PM

                                          @konstanti There is only this one, single rule ..... !

                                          K 1 Reply Last reply Feb 3, 2019, 5:02 PM Reply Quote 0
                                          20 out of 24
                                          • First post
                                            20/24
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received