Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    My Security Cams do not working

    Scheduled Pinned Locked Moved General pfSense Questions
    28 Posts 5 Posters 2.7k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      am.steen
      last edited by

      I have Security Cams behind pfsense and it works from internet after port forward, now from my LAN I can ping it but fail to connect to NVR.

      I try direct without pfsense and it connect.
      I try to add LAN firewall rule for it but I fail.
      My cams NVR: 172.30.7.235
      My cams gateway: 172.30.7.245 ( pfsense Lan )
      Client pc with NVR software on different subnet: 172.30.5.0/24
      Client pc Can ping NVR IP But fail to connect to NVR.

      Please help

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN Offline
        NollipfSense @am.steen
        last edited by

        @am-steen said in My Security Cams do not working:

        Client pc with NVR software on different subnet: 172.30.5.0/24

        There is no route to that different subnet. How do you expects to connect! Read: https://docs.netgate.com/pfsense/en/latest/config/factory-defaults.html

        Then here: https://docs.netgate.com/pfsense/en/latest/firewall/best-practices.html

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        A 1 Reply Last reply Reply Quote 0
        • A Offline
          am.steen @NollipfSense
          last edited by

          @nollipfsense
          If there is no routes then how I could ping NVR from these vlans.
          I can ping but I fail to connect to NVR

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @am.steen
            last edited by

            What are your rules you have on this vlan your trying to connect to the NVR from?

            Forcing traffic out a gateway for sure cause the exact issue your describing.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              am.steen @johnpoz
              last edited by

              @johnpoz
              Ok I add a new network Card same VLAN as NVR
              I create a new firewall pass rule for by passing this VLAN 172.30.5.0 to
              NVR 172.30.7.235 Vlan
              But I Fail.

              Can I have help about that rule please ??

              JKnottJ johnpozJ 2 Replies Last reply Reply Quote 0
              • JKnottJ Offline
                JKnott @am.steen
                last edited by

                @am-steen

                Does that NVR have 2 ports? If so, you're supposed to connect one to the same subnet as the cameras and the other to the rest of your network.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                A 1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator @am.steen
                  last edited by johnpoz

                  @am-steen said in My Security Cams do not working:

                  Can I have help about that rule please ??

                  Dude post a picture of your rules you created..

                  If you created a rule to allow the traffic then it would be allowed. Unless you are policy routing out some gateway or vpn. Sniff to validate the traffic going - maybe its just your nvr not answering..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  A 1 Reply Last reply Reply Quote 0
                  • A Offline
                    am.steen @JKnott
                    last edited by

                    @jknott
                    NO I only have one network port on my NVR

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      am.steen @johnpoz
                      last edited by

                      @johnpoz

                      This is new int. VLAN5 with IP from that vlan5

                      1.jpg

                      And this is the rule to access NVR on different VLAN7

                      2.jpg

                      And this is rule settings

                      3.jpg

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN Offline
                        NogBadTheBad @am.steen
                        last edited by NogBadTheBad

                        @am-steen Is the protocol correct ?

                        Try any, then if that work try tcp/udp.

                        You could do a packet capture on the host on the LAN or on the pfSense LAN interface to see what the requirements are if you don't know what protocol & ports.

                        Screenshot 2021-05-03 at 12.39.42.png

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator @NogBadTheBad
                          last edited by johnpoz

                          That rule shows no hits 0/0 - you sure your source IP is correct to allow what your wanting to allow?

                          You say you can ping - well something else is going on then. Because your rule is tcp only - so no ping would be allowed.

                          edit: If you want some client to talk to to your NVR.. Then the rule would be on the interface the client is connected too. Not on the NVR interface.

                          Rules are evaluated as traffic enters pfsense from the network its attached to.. First rule to trigger wins no other rules are evaluated.

                          If you want something to talk to vlanX from Lan - then the rule would be on the lan interface. There would be no rules required on the vlanX interface to allow that to work.

                          What network is 172.30.7 and what network is 172.30.5? Putting a rule on 172.30.5 to allow something to talk to it from 173.30.7 is not correct. The rule would be on 172.30.7 interface to allow traffic to 172.30.5

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          A 1 Reply Last reply Reply Quote 0
                          • A Offline
                            am.steen @johnpoz
                            last edited by

                            @johnpoz
                            Ok this is my last rule update
                            5.jpg

                            and this is firewall logs related to this pc

                            4.jpg

                            Any suggestions

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ Offline
                              johnpoz LAYER 8 Global Moderator @am.steen
                              last edited by johnpoz

                              And you have an asymmetrical problem.. Your seeing SA (syn,ack) not syn blocks.

                              How exactly do you have this wired?

                              So 5.245 tried to talk to 7.235, sends a syn to port 3761, then 7.235 answers back with syn,ack - but pfsense never saw the syn to open the state.

                              https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              NogBadTheBadN A 2 Replies Last reply Reply Quote 0
                              • NogBadTheBadN Offline
                                NogBadTheBad @johnpoz
                                last edited by NogBadTheBad

                                Are both subnets directly connected to your pfSense router, just wanting to double check?

                                I notice from a prevoius post you have multiple routers:-

                                https://forum.netgate.com/topic/163325/can-not-forward-rdp-port-behind-a-router/3?_=1620123172825

                                "Public IP ==> CISCO ==> VLAN 2 ==>172.30.2.100 ==> Pfsense ==> VLAN7 ==> 172.30.7.245 ==> local PC ==> 172.30.7.60"

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                A 1 Reply Last reply Reply Quote 0
                                • A Offline
                                  am.steen @NogBadTheBad
                                  last edited by

                                  @nogbadthebad
                                  I modify everything since that post
                                  Public IP ==> CISCO ==> VLAN 7 ==>192.168.60.100 ==> Pfsense ==> VLAN7 ==> 172.30.7.245 ==> local PC ==> another VLAN5 == >172.30.5.245

                                  1 Reply Last reply Reply Quote 0
                                  • A Offline
                                    am.steen @johnpoz
                                    last edited by am.steen

                                    @johnpoz
                                    Very sorry as I am Beginner at pfsense so I can not understand asymmetrical problem,
                                    How To solve this, known that I can ping 172.30.7.235 from the pc 172.30.5.245
                                    Another info. I cannot connect to NVR with web interface.
                                    What is the suitable firewall rule to fix this asymmetrical problem ??

                                    johnpozJ 1 Reply Last reply Reply Quote 0
                                    • johnpozJ Offline
                                      johnpoz LAYER 8 Global Moderator @am.steen
                                      last edited by

                                      @am-steen said in My Security Cams do not working:

                                      What is the suitable firewall rule to fix this asymmetrical problem ??

                                      That is not how you fix an asymmetrical problem.

                                      How do you have this wired together.. If these were 2 vlans attached to pfsense - then it would be impossible to have an asymmetrical problem. Unless your vlans are not actually isolated..

                                      You see a SA block, when pfsense never saw the SYN (S) to create the state.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      A 1 Reply Last reply Reply Quote 0
                                      • A Offline
                                        am.steen @johnpoz
                                        last edited by

                                        @johnpoz
                                        Yes there are 2 VLANS connected to my pfsense and as you say are not actually isolated..
                                        They have interconnecting through my cisco router.

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • johnpozJ Offline
                                          johnpoz LAYER 8 Global Moderator @am.steen
                                          last edited by

                                          @am-steen said in My Security Cams do not working:

                                          They have interconnecting through my cisco router.

                                          What? You need to draw how you have things actually connected if you want anyone to be able to help you.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          A 1 Reply Last reply Reply Quote 0
                                          • A Offline
                                            am.steen @johnpoz
                                            last edited by

                                            @johnpoz

                                            Public IP ==> CISCO ==> VLAN 7 ==>192.168.60.100-LAN ==> Pfsense Vmachine ==> LAN-VLAN7 ==> 172.30.7.245 ==> VLAN5-local PC ==> == >172.30.5.245

                                            johnpozJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.