Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    [Why] pfSense doesn't port-forward with gateway group set as default?

    Scheduled Pinned Locked Moved NAT
    2 Posts 2 Posters 307 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • senseivitaS
      senseivita
      last edited by

      I had written a full message complete with diagnostics and all I did to where I was, while taking the screenshots I rechecked/retested everything as I went to waste less of people's time and y'know...look a little less dumb when it was pointed out to be something trivial 😅 and I discovered it was the gateway group set as default. So...um yeah.

      Everything works perfectly fine with the gateway group set as default, why do port forwards don't?

      While detailing the setup, in my original messaged I had written that those hosts I wanted to access don't have access to the Internet except via their reply-to rule that's created on-the-fly by a port forward. This is now what I don't understand, don't they must get this rule? I changed the default gateways and tried to access again via the same interface, it worked fine, then again and again.

      So the reply-to is working otherwise the traffic would've followed the default route set on another interface, wouldn't it?? Obviously I'm still far from understanding all of the TCP/IP stack, so could you explain this to me?

      0_1549408802119_Screen Shot 2019-02-05 at 16.19.58.png

      Thanks! :)

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Having the same gateway on multiple interfaces is likely the problem. It works, sort of, with PPPoE, but it's not a configuration we recommend or technically support, due to issues like this.

        Probably the requests are coming in one interface and then it can't figure out which way to send the replies.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 1
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.