Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port forwarding to Web server on Server VLAN

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 664 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dzacharias
      last edited by dzacharias

      Was hoping to get some guidance on how to configure this firewall. Some background first. I am using a Cisco L3 Switch and have configured a few VLANs on it. Client VLAN and Server VLAN, however, I am using pfsense to do the routing. I used this guide to get it working. https://greigmitchell.co.uk/2019/08/configuring-intervlan-routing-with-a-layer-3-switch-and-pfsense

      This setup works great internally. I can get to other clients/IP addresses within the network and I can get to the internet from each VLAN/network as well, however, I cannot seem to get port forwarding working properly. I have confirmed that the ports are open with an external port checker. It's like the port is open, but the traffic is not getting to the proper server/service on the respective VLAN that the server is on.
      I open the ports using the following method. Firewall>NAT>Port Forward I created a rule and the port is open, but the traffic is not reaching its intended destination. I have also confirmed that the web server is working internally and listening for requests. PLEASE HELP!

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        @dzacharias said in Port forwarding to Web server on Server VLAN:

        I have confirmed that the ports are open with an external port checker.

        but the traffic is not getting to the proper server/service on the respective VLAN that the server is on.

        Not really possible.. If your outside source shows that port is opened, then that means something answered.. So that means the traffic got to where you forwarded it, pfsense sure isn't going to answer your port that your forwarded. You are testing tcp right, there is really no reliable online testing for udp ports.

        Possible something in front of pfsense answered it, and pfsense never saw the traffic... I would suggest you actually validate pfsense sees the traffic on its wan.. This is really step one in any port forwarding troubleshooting... shoot you really should do that before you even attempt to create the port forward.

        https://docs.netgate.com/pfsense/en/latest/troubleshooting/nat.html

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • D
          dzacharias
          last edited by

          @johnpoz said in Port forwarding to Web server on Server VLAN:

          pfsense sure isn't going to answer your port that your forwarded.

          dzacharias Laughed at "pfsense sure isn't going to answer your port that your forwarded."

          Interesting, perhaps I can check the logs of the web server to see if it answered my request.
          How can I check to see if pfsense is seeing my request?
          Thank you in advance!

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @dzacharias
            last edited by

            @dzacharias said in Port forwarding to Web server on Server VLAN:

            How can I check to see if pfsense is seeing my request?

            You can use Diagnostic > Packet Capture. Select the proper VLAN interface and filter to the webserver IP and ports.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              That would be the second check, first check your wan interface to make sure the traffic even gets to pfsense, pfsense can not forward what it doesn't see.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.