Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port Forwarding Help

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 631 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      netboy
      last edited by netboy

      Hey I am sure I am doing something wrong.....
      I followed the guide here for port forwarding.
      Based on my port forwarding Firewall / NAT / Port Forward. a rule was "auto generated" by pfsense. Here is the screen shot: I have blanked out the Local IP and port.

      8fbe756a-cdf8-4640-8909-1e58da031898-image.png

      When I check if my port is open using URL the port is closed.

      Am I missing something. FYI, this is for QuickConnect for Synology.

      Also curios: Why is my WAN IP "different" from the IP reported by whatsmyip.org? The reason I am asking is I read something about cgnat Which I do not understand. pfsense WAN IP is something like 100.72.xxx.xxx and Whatsmyip reports totally different 216.xxx.xxx.xxx

      I love youtube! I viewed about cgnat here and now I understand.

      Based on the youtube video should I get a STATIC IP from my provider? Or is there any alternative way to port forward with cgnat?

      V johnpozJ 2 Replies Last reply Reply Quote 0
      • V
        viragomann @netboy
        last edited by

        @netboy said in Port Forwarding Help:

        Also curios: Why is my WAN IP "different" from the IP reported by whatsmyip.org? The reason I am asking is I read something about cgnat

        Yes, this indicates that your WAN IP is a CC-NAT.

        There is mo possibility to access it from the internet, because there is a router in front of it, which doesn’t forward anything.

        So you can try to get a public IP, but you might have to pay for it.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @netboy
          last edited by johnpoz

          @netboy said in Port Forwarding Help:

          this is for QuickConnect for Synology.

          quick connect does not require a port forward to work. It makes an outbound connection to synology, and when you connect you come through the relay service. It does try and do a hole punch, but if your behind a nat then the relay service should be used.

          relay.jpg

          You can read their white paper on how it works.

          https://global.download.synology.com/download/Document/Software/WhitePaper/Firmware/DSM/All/enu/Synology_QuickConnect_White_Paper.pdf

          Being behind a nat or even a cgnat should still work via the relay service - might not be all that fast.. But it should work.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          N 1 Reply Last reply Reply Quote 0
          • N
            netboy @johnpoz
            last edited by

            @johnpoz said in Port Forwarding Help:

            Being behind a nat or even a cgnat should still work via the relay service - might not be all that fast.. But it should work.

            Yes! I had turned on local only in Iphone - Did not realize it! It does work but very slow....Will it be faster if I get a static IP and port forward?

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @netboy
              last edited by johnpoz

              @netboy if you can get a direct connection then yeah should be faster, but it does a hole punch - you wouldn't actually have to setup a port forward for it to work. But yeah your IP needs to be reachable. Which behind a cgnat its not.

              While a port forward should make it an easier connection to make - hole punch is valid way of coming back in through the connection that a client makes. So you don't actually have to allow for unsolicited traffic via a port forward.

              If you go and get a actual IP, doesn't have to be "static" just not behind a cgnat.. I would setup a vpn vs using their quick connect.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              N 1 Reply Last reply Reply Quote 0
              • N
                netboy @johnpoz
                last edited by

                @johnpoz said in Port Forwarding Help:

                I would setup a vpn vs using their quick connect.

                I heard about tailscale? Can I try this?

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @netboy
                  last edited by johnpoz

                  @netboy that might work behind a cgnat sure. You could try that.

                  https://tailscale.com/blog/how-nat-traversal-works/

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  N 1 Reply Last reply Reply Quote 0
                  • N
                    netboy @johnpoz
                    last edited by

                    @johnpoz Tailscale works like a charm

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.