Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT-PMP Failures

    Scheduled Pinned Locked Moved NAT
    3 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antiquity2489
      last edited by

      Recently started using pfSense on my home network and am trying to allow direct connections between my local and remote Tailscale VPN devices. Without going into specifics, all I should have to do is enable NAT-PMP and Tailscale should create the mappings it needs. However, all I get are these errors:

      May 13 15:09:09 miniupnpd 60278 PCP MAP: failed to add mapping UDP 41641->192.168.1.106:41641 ‘PCP MAP d0a44ffed131cc9e7a291b9d’
      
      May 13 15:09:09 miniupnpd 60278 Failed to add NAT-PMP 41641 udp->192.168.1.106:41641 ‘NAT-PMP 41641 udp’
      

      Tailscale gives me this error:

      2022/05/13 15:01:31 portmap: PMP probe failed due result code: {OpCode:128 ResultCode:NetworkFailure SecondsSinceEpoch:161 MappingValidSeconds:0 InternalPort:0 ExternalPort:0 PublicAddr:0.0.0.0}
      2022/05/13 15:01:31 portmap: [v1] Got PCP response: epoch: 161
      

      No mappings get created and the log just fills up. I'm not sure if this is a pfSense or Tailscale issue. I posted on the Tailscale forums as well and was able to implement a workaround with manual mappings, but I'm still not sure what's causing the issue.

      My setup is pretty basic so far. I tried a fresh install of OPNsense just to compare and I get the same error messages. Any help would be appreciated.

      1 Reply Last reply Reply Quote 0
      • A
        Antiquity2489
        last edited by

        Can someone at least tell me why the mappings might be failing?

        Bob.DigB 1 Reply Last reply Reply Quote 0
        • Bob.DigB
          Bob.Dig LAYER 8 @Antiquity2489
          last edited by Bob.Dig

          @antiquity2489 I can't but UPnP never was a strength of *Sense. So you better make a port forward yourself.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.