Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Only Some of my Port Forwards work ?

    Scheduled Pinned Locked Moved Firewalling
    43 Posts 3 Posters 5.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cire3
      last edited by

      Not Working.PNG

      This one is not working.

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Are you providing a VOIP server locally?

        If the phone is local and the VOIP server remote you shouldn't need any sort of port forwards, I have a VOIP phone local and don't have any port forwards.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        C 1 Reply Last reply Reply Quote 0
        • C
          Cire3 @NogBadTheBad
          last edited by Cire3

          @nogbadthebad From my understanding the phone server is on site (Some Panasonic System) and the phone is off site (Cell Phone). Backwards in my opinion, but I believe they want to have a business phone in another location. I would use a server off site, not sure what he was sold or why.

          This port forward is squeezing my brain though.

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @Cire3
            last edited by NogBadTheBad

            @cire3 Try killing the firewall states.

            Diagnostics -> States -> Reset States

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            C 1 Reply Last reply Reply Quote 0
            • C
              Cire3 @NogBadTheBad
              last edited by

              @nogbadthebad Yea, just tried that a little bit ago. Same issue.

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @Cire3
                last edited by

                @cire3

                Those rules aren't disabled are they, there is a mini square in the tick box ?

                I don't use that colour scheme.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                C 1 Reply Last reply Reply Quote 0
                • C
                  Cire3 @NogBadTheBad
                  last edited by

                  @nogbadthebad 9300 RUle.PNG

                  My 9300 rule that auto populated when setting up NAT Port Forward

                  NogBadTheBadN 1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad @Cire3
                    last edited by NogBadTheBad

                    @cire3 I'd start doing a packet capture on the WAN interface to see if the packets are hitting the WAN interface, maybe the ISP is blocking some of the ports.

                    Also I was talking about the NAT rule with the mini square not the firewall rule.

                    Screenshot 2021-06-21 at 19.59.37.png

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      Cire3 @NogBadTheBad
                      last edited by

                      @nogbadthebad said in Only Some of my Port Forwards work ?:

                      packet capture on the WAN

                      Sorry, thought you wanted rule, as I already posted the NAT Forward rules. My bad. However I double checked.

                      I'm connected over VPN, and know enough to be dangerous...lol Any way I can packet capture on the WAN remote ? Never had to do this.

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @Cire3
                        last edited by

                        @cire3 yup have a look at the diagnostics section.

                        You can download the packet capture from the page and view in wireshark.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        C 1 Reply Last reply Reply Quote 0
                        • C
                          Cire3 @NogBadTheBad
                          last edited by

                          @nogbadthebad Just seen it after I asked the question. Way cool. Downloading now after trying to check port.

                          C 1 Reply Last reply Reply Quote 0
                          • C
                            Cire3 @Cire3
                            last edited by

                            @cire3 Host address being my Static WAN ? And should I use a port or just capture?

                            C 1 Reply Last reply Reply Quote 0
                            • C
                              Cire3 @Cire3
                              last edited by

                              @cire3 Packate Capture 9300.PNG

                              And this from PFSense :

                              15:25:00.282522 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                              15:25:01.278833 IP 198.199.98.246.50719 > 198.0.115.21.9300: tcp 0
                              15:25:01.283582 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                              15:25:02.282636 IP 198.199.98.246.50724 > 198.0.115.21.9300: tcp 0
                              15:25:02.284759 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                              15:25:03.282818 IP 198.199.98.246.50731 > 198.0.115.21.9300: tcp 0
                              15:25:56.035819 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                              15:25:57.034127 IP 198.199.98.246.50880 > 198.0.115.21.9300: tcp 0
                              15:25:57.036750 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                              15:25:58.034059 IP 198.199.98.246.50883 > 198.0.115.21.9300: tcp 0
                              15:25:58.038290 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                              15:25:59.038237 IP 198.199.98.246.50889 > 198.0.115.21.9300: tcp 0
                              15:26:00.276783 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                              15:26:01.274091 IP 198.199.98.246.50895 > 198.0.115.21.9300: tcp 0
                              15:26:01.277837 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                              15:26:02.273897 IP 198.199.98.246.50897 > 198.0.115.21.9300: tcp 0
                              15:26:02.278893 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0
                              15:26:03.277951 IP 198.199.98.246.50899 > 198.0.115.21.9300: tcp 0

                              NogBadTheBadN 1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN
                                NogBadTheBad @Cire3
                                last edited by

                                @cire3 OK so it looks like 9300 is hitting the WAN interface.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                C 1 Reply Last reply Reply Quote 0
                                • C
                                  Cire3 @NogBadTheBad
                                  last edited by

                                  @nogbadthebad Yea, It would have been great to blame Comcast. Not today I guess...lol

                                  C 1 Reply Last reply Reply Quote 0
                                  • C
                                    Cire3 @Cire3
                                    last edited by

                                    @cire3 Firewall Rules WAN.PNG

                                    Figured I would post in case something didn't look right

                                    C NogBadTheBadN 2 Replies Last reply Reply Quote 0
                                    • C
                                      Cire3 @Cire3
                                      last edited by

                                      @cire3 States.PNG

                                      This is what's back in states

                                      1 Reply Last reply Reply Quote 0
                                      • NogBadTheBadN
                                        NogBadTheBad @Cire3
                                        last edited by NogBadTheBad

                                        @cire3 Rules are read from the top down, I suggest you have a read:-

                                        https://docs.netgate.com/pfsense/en/latest/firewall/rule-list-intro.html

                                        Everything TCP will hit the 3rd rule down.

                                        Andy

                                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                        C 2 Replies Last reply Reply Quote 0
                                        • C
                                          Cire3 @NogBadTheBad
                                          last edited by

                                          @nogbadthebad Reset States again, waiting for it to boot back up and VPN in

                                          1 Reply Last reply Reply Quote 0
                                          • C
                                            Cire3 @NogBadTheBad
                                            last edited by

                                            @nogbadthebad UDP to TCP/UDP to TCP. No change

                                            NogBadTheBadN 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.