Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to monitor specific port forwarded traffic

    Scheduled Pinned Locked Moved NAT
    port forwardmontoring
    4 Posts 3 Posters 755 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gertty
      last edited by

      I have a device that I am letting do NAT-PMP and uPnP. Once the device boots, pfSense shows a NAT-PMP rule for that expected IP. Let's say the mapping ends up being:

      ext port  proto   int ip     int port
      34567     tcp     10.1.1.35  55000	
      

      What I would like to do is see two things:

      1. Incoming traffic to the WAN interface on port 3456.
      2. traffic going out the correct VLAN interface to dest 10.1.1.35:5500

      At a minimum, I'd like just some "proof-of-line" showing traffic doing that. But ideally I could get see some packet or byte counts, maybe using pftop (but I'll take what I can get)

      Is there an easy way to do this with a stock 2.4.4-RELEASE-p3 build?

      1 Reply Last reply Reply Quote 0
      • JeGrJ
        JeGr LAYER 8 Moderator
        last edited by

        Not with stock IMHO but it's no problem doing that with the softflow package. You only need a netflow client tool to display the infos. Or you could try ntop-ng that should show those infos, too.

        Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

        If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

        1 Reply Last reply Reply Quote 1
        • ?
          A Former User
          last edited by

          Could you do the port forward manually and then on the resulting firewall rule allowing that traffic tick the box to log that traffic?

          1 Reply Last reply Reply Quote 0
          • G
            gertty
            last edited by

            What I ended up doing was using pftop, filtering on the dst port (which should be the internal port on the internal host), and looking for established connections.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.