Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall & forwarding

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 3 Posters 10.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jesse7
      last edited by

      But you can acess it via the external IP from inside your lan?  But if you use someone else net connection you can't?

      Might be something to do with that reflection option that was added recently try turn that off,  turning it off will probably have the oposite effect what I just typed above.  Or it may just stop you acessing it from you LAN.

      OK so you have edited your post to make it more clear .. glad I noticed and didn't just reply blindly.

      1 Reply Last reply Reply Quote 0
      • C
        Cyrandir
        last edited by

        I'm certainly willing to try it, I've been beating my head against this for a couple of days now.  I'll be back in a bit with the results.

        1 Reply Last reply Reply Quote 0
        • C
          Cyrandir
          last edited by

          I think I got it turned off an no joy.  Is there more than one place to turn this feature off?  Or does anyone have any other ideas?

          1 Reply Last reply Reply Quote 0
          • J
            Jesse7
            last edited by

            Can you post your rules?

            Oh also can you confirm you are not able to access it from a seperate Net connection that has nothing to do with your pf/wan/lan setup.

            1 Reply Last reply Reply Quote 0
            • J
              Jesse7
              last edited by

              @Cyrandir:

              I think I got it turned off an no joy.  Is there more than one place to turn this feature off?  Or does anyone have any other ideas?

              Out of curiousity when you turned off that feature, could you still acess via your external IP from your LAN?

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                First delete the rule you created for the webserver and the nat entry. Then start over again. Go to Firewall>NAT and add a port forward.

                Interface: WAN
                External Adress: Interface Adress
                Protocol: TCP
                External Portrange: HTTP
                NAT IP: <lan ip="" of="" your="" webserver="">Local Port: 80
                Description: whatever you like

                Auto add a firewall rule <–---------------------this is important. it will create the correct rule for you. You can create it manually but why if it does it automagically. Less to do wrong ;-)

                Save and apply. You should be up now. If not check if your DynDNS resolves to the correct WAN IP.</lan>

                1 Reply Last reply Reply Quote 0
                • C
                  Cyrandir
                  last edited by

                  Jessie7:  No I was not able to see things from the external IP.  The reflect thing seems to be working properly.

                  Hoba:  That is exactly how I created things the first time.  I'll try it again from scratch though.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Cyrandir
                    last edited by

                    Guess I should have mentioned this earlier, but I'm running a ventrilo server from the same machine and the NAT/rules created seem to be doing their job.  I and others can connect via external IP and by DNS name without any problems.  Other than the port numbers the rules etc are identical, but not working for port 80.  I'm heading off now to rebuild the rules from scratch.  Wish me luck.

                    1 Reply Last reply Reply Quote 0
                    • C
                      Cyrandir
                      last edited by

                      Upon much further investigation. I've found that my ISP blocks incoming connections on port 80, along with many other common alternatives, such as 1080 and 8080.  I guess I'll just have to set it up for another port.  In the end, I can only be glad it wasn't a configuration error on my part, and I'm not going mad.  Thank you everyone for your help.

                      1 Reply Last reply Reply Quote 0
                      • C
                        Cyrandir
                        last edited by

                        Final update, I got it to work by switching to external port 6360, randomly picked off a chart of assigned ports.  If anyone has similar problems, feel free to PM me and I'll help you through it.  Thanks again everyone!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.