Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense 2.5.0.a.20201127.0650 NAT Issues

    Scheduled Pinned Locked Moved NAT
    22 Posts 4 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dragoangelD
      dragoangel @stephenw10
      last edited by

      @stephenw10 said in pfSense 2.5.0.a.20201127.0650 NAT Issues:

      You gateway groups are not being populated in the ruleset. The only reason that should ever happen normally is if you have not set Skip rules when gateway is down and all the gateways were down. Which clearly isn't the case here.

      Yes, this isn't the case. I not see any bit of traffic when dump WAN TIER1 while trying connect to WAN TIER2. Can it be due promiscuous mode isn't enabled? I doesn't think so.

      Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
      Unifi AP-AC-LR with EAP RADIUS, US-24

      dragoangelD 1 Reply Last reply Reply Quote 0
      • dragoangelD
        dragoangel @dragoangel
        last edited by

        @stephenw10 send pfSense status report to your email

        Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
        Unifi AP-AC-LR with EAP RADIUS, US-24

        1 Reply Last reply Reply Quote 0
        • dragoangelD
          dragoangel @stephenw10
          last edited by

          Hi, @stephenw10 I done full reinstall from scratch to 2.4.5_p1 on ssd and updated to 2.5.0.a.20201127.0650 and restored from backup - still same issue with:

          GWWANGROUP = "  "
          GWWANGROUP6 = "  "
          

          I also found in logs:

          Jan 5 00:16:21 	php-fpm 	97323 	/rc.filter_configure_sync: An error occurred while trying to find the interface got `MyMainIPv6GWIP`. The rule has not been added.
          Jan 5 00:16:21 	php-fpm 	97323 	/rc.filter_configure_sync: An error occurred while trying to find the interface got `MyMainIPv4GWIP`. The rule has not been added. 
          

          Maybe this root case why I have this?

          Also want to note: when I restore from backup - if I used console\terminal it always "merges" in strange way my xg7100u switch configs and break everything, due to this reinstall takes for me crazy long and was successful only on second time. It will be cool if pfsense on terminal also ask about preserving switch conf or not.

          Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
          Unifi AP-AC-LR with EAP RADIUS, US-24

          dragoangelD 1 Reply Last reply Reply Quote 0
          • dragoangelD
            dragoangel @dragoangel
            last edited by

            @stephenw10 can you please help with this issue? It still in place. Also I doesn't receive any updates on my development 2.5 pfsense even that comes on 2.4.5_p1 stable (on another xg7100u).

            Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
            Unifi AP-AC-LR with EAP RADIUS, US-24

            1 Reply Last reply Reply Quote 1
            • S
              saeed
              last edited by

              Hi,
              after upgrading to 2.5.1 my port forwards only works for active wan. is it related to this bug?
              any solution?

              dragoangelD 1 Reply Last reply Reply Quote 0
              • dragoangelD
                dragoangel @saeed
                last edited by

                @saeed you need update to latest version and it will fix nat, but not NPt for ipv6.

                Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                Unifi AP-AC-LR with EAP RADIUS, US-24

                S 2 Replies Last reply Reply Quote 0
                • S
                  saeed @dragoangel
                  last edited by

                  @dragoangel said in pfSense 2.5.0.a.20201127.0650 NAT Issues:

                  you need update to latest version and it will fix nat, but not NPt for ipv6.

                  it's a production server and already updated to 2.5.1
                  you mean update to latest development snapshot?

                  1 Reply Last reply Reply Quote 0
                  • S
                    saeed @dragoangel
                    last edited by

                    @dragoangel
                    https://redmine.pfsense.org/issues/11805

                    dragoangelD 1 Reply Last reply Reply Quote 0
                    • dragoangelD
                      dragoangel @saeed
                      last edited by

                      @saeed I have pfsense plus so for me firmware is 21.02.2. For CE, yes - it still unresolved.

                      Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                      Unifi AP-AC-LR with EAP RADIUS, US-24

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Despite extensive testing before release it's still possible to hit this in 2.5.1 CE but not as far as we know in 21.02.2 (Plus). Though it's unclear what the difference there is.
                        https://redmine.pfsense.org/issues/11805

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.