Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Tried everything port forwarding not working??

    NAT
    4
    42
    5.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Djinn1
      last edited by Djinn1

      Hi everyone.

      Yesterday I tried for at least 6 hour to get the port forwarding to work but nothing. I have tried the troubleshooting guide and what I know I did everything correct.
      I want to port forward port 8080 and I have these setting.

      https://imgur.com/a/DuGoRSl

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        The destination should be WAN Address, not any.

        Other than that it looks reasonable.

        Are you positive the traffic is even arriving on WAN:8080?

        Good list of things to check (really check) here:

        https://www.netgate.com/docs/pfsense/nat/port-forward-troubleshooting.html

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        D 1 Reply Last reply Reply Quote 0
        • D
          Djinn1 @Derelict
          last edited by Djinn1

          @derelict trust me tried that. Forgot to change before screenshoot. That not the issue here.

          What you mean if traffic arriving on Wan?

          DerelictD 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            0_1551259122431_Screenshot 2019-02-27 at 09.17.22.png

            Firewall rule on the WAN interface ?

            0_1551259213613_Screenshot 2019-02-27 at 09.19.31.png

            Do a packet capture on the WAN for port 8080.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            D 1 Reply Last reply Reply Quote 0
            • D
              Djinn1 @NogBadTheBad
              last edited by Djinn1

              No nothing actually. I think because it's not in use maybe? I trying to open a port for a game.

              0_1551264858771_port.JPG

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by

                Do you have a RFC1918 address on your WAN interface ?

                https://tools.ietf.org/html/rfc1918

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                D 1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate @Djinn1
                  last edited by Derelict

                  @djinn1 said in Tried everything port forwarding not working??:

                  trust me tried that. Forgot to change before screenshoot. That not the issue here.
                  What you mean if traffic arriving on Wan?

                  If you had actually tried that you would not be asking this question.

                  It is step number 5 in the list of things to check there.

                  Packet capture on WAN for traffic to port 8080 and attempt a connection. Is the SYN there?

                  If not, it is blocked upstream. If so, packet capture on LAN for port 8080 and test again. Is the SYN forwarded to the inside host? If so, the port forward is working. Is there a response? If not, go to that host and figure out why it is not responding.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  D 1 Reply Last reply Reply Quote 0
                  • D
                    Djinn1 @NogBadTheBad
                    last edited by

                    @nogbadthebad Yes its there.

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • D
                      Djinn1 @Derelict
                      last edited by

                      @derelict Hi, you need to explain it a little bit esier. I am not a pro, I have basic network knowledge.

                      1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @Djinn1
                        last edited by

                        @djinn1

                        Yes what’s there?

                        If your saying your WAN address is a RFC1918 address your pfSense box is connected to another router, that’s probably why the port forward isn’t working and also why you don’t see any hits on the firewall rule / packet capture.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        D 1 Reply Last reply Reply Quote 0
                        • D
                          Djinn1 @NogBadTheBad
                          last edited by

                          @nogbadthebad My pfsense is only router connected. no other router in the house.

                          0_1551290299222_port.JPG

                          1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN
                            NogBadTheBad
                            last edited by NogBadTheBad

                            The order of the 3rd and 4th rule needs swapping round.

                            Firewall rules are read from top to bottom and why have you set a gateway

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            D 1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Not really. After the port forward translates the destination address the 54-65535 rule will not match.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              D 1 Reply Last reply Reply Quote 1
                              • D
                                Djinn1 @NogBadTheBad
                                last edited by Djinn1

                                @nogbadthebad Because I have a VPN on the other subnet.

                                I have reset all my Pfsense box nothing installed and only port forward the 8080 an still not open.0_1551291244136_port.JPG0_1551291411440_port.JPG

                                1 Reply Last reply Reply Quote 0
                                • D
                                  Djinn1 @Derelict
                                  last edited by

                                  @derelict That one is other subnet.

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    Packet capture on the INSIDE 192.168.1.0 interface for traffic to 192.168.1.100 port 8080 and test again. Is the traffic there?

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    D 1 Reply Last reply Reply Quote 0
                                    • D
                                      Djinn1 @Derelict
                                      last edited by

                                      @derelict how?

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate
                                        last edited by Derelict

                                        Diagnostics > Packet Capture
                                        Interface: WAN
                                        Protocol: TCP
                                        Port: 8080
                                        Count: 10000

                                        Start

                                        Run your tests connecting to WAN:8080 from the outside.

                                        Diagnostics > Packet Capture

                                        Stop

                                        What is displayed at the bottom?

                                        THEN:

                                        Diagnostics > Packet Capture
                                        Interface: LAN
                                        Host Address: 192.168.1.100
                                        Protocol: TCP
                                        Port: 8080
                                        Count: 10000

                                        Start

                                        Run your tests connecting to WAN:8080 from the outside.

                                        Diagnostics > Packet Capture

                                        Stop

                                        What is displayed at the bottom?

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        D 1 Reply Last reply Reply Quote 0
                                        • D
                                          Djinn1 @Derelict
                                          last edited by

                                          @derelict Ok done that what is correct and whats not? Because my ip is there don´t want to share screen.

                                          1 Reply Last reply Reply Quote 0
                                          • DerelictD
                                            Derelict LAYER 8 Netgate
                                            last edited by

                                            So copy and paste it into a text editor and search and replace for the first three octets of your WAN address substituting something like a.b.c and post the results.

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            D 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.