Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 3 Posters 3.3k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      viragomann @morgenstern
      last edited by

      @morgenstern
      So what is the sense of forwarding it? That doesn't it even more secure.
      Simply allow access to the WAN from the certain source IPs.

      morgensternM 1 Reply Last reply Reply Quote 0
      • morgensternM Offline
        morgenstern @viragomann
        last edited by

        @viragomann I originally copied that approach from a contractor that had set it up that way for us a few years back. I never thought to try and simplify it when it worked... :)

        1 Reply Last reply Reply Quote 0
        • SteveITSS Offline
          SteveITS Rebel Alliance @morgenstern
          last edited by

          @morgenstern If it's a consumer grade account I could definitely see them blocking server connections. If it's CGNAT (100.64.0.0/10 subnet) like Starlink uses for IPv4 then it isn't going to work for any inbound connection...try IPv6 if they provide that.

          To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Only install packages for your version of pfSense.
          Upvote ๐Ÿ‘ helpful posts!

          morgensternM 1 Reply Last reply Reply Quote 0
          • morgensternM Offline
            morgenstern
            last edited by

            87305fb8-ab5a-458b-b27d-f88ea3d7b449-image.png

            Deleted the NAT rule and just added this WAN rule instead but no joy

            1 Reply Last reply Reply Quote 0
            • morgensternM Offline
              morgenstern @SteveITS
              last edited by

              @steveits said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

              @morgenstern If it's a consumer grade account I could definitely see them blocking server connections. If it's CGNAT (100.64.0.0/10 subnet) like Starlink uses for IPv4 then it isn't going to work for any inbound connection...try IPv6 if they provide that.

              I guess I may have to speak to them. How would I establish whether it's this CGNAT? Is it a common thing nowadays?

              V 1 Reply Last reply Reply Quote 0
              • morgensternM Offline
                morgenstern
                last edited by

                It's a /29 network by the way

                1 Reply Last reply Reply Quote 0
                • V Offline
                  viragomann @morgenstern
                  last edited by

                  @morgenstern
                  https://en.wikipedia.org/wiki/Carrier-grade_NAT

                  https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses

                  morgensternM 1 Reply Last reply Reply Quote 0
                  • morgensternM Offline
                    morgenstern @viragomann
                    last edited by

                    @viragomann said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                    @morgenstern
                    https://en.wikipedia.org/wiki/Carrier-grade_NAT

                    https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses

                    Ah yeah, I see what you mean:

                    In April 2012, IANA allocated the block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255, netmask 255.192.0.0) for use in carrier-grade NAT scenarios.

                    The public IP I got isn't in that range.

                    V 1 Reply Last reply Reply Quote 0
                    • V Offline
                      viragomann @morgenstern
                      last edited by viragomann

                      @morgenstern

                      In April 2012, IANA allocated the block 100.64.0.0/10 (100.64.0.0 to 100.127.255.255, netmask 255.192.0.0) for use in carrier-grade NAT scenarios.

                      The public IP I got isn't in that range.

                      And also not a RFC 1918?

                      So check if the packets even arrive on your WAN. You can use Diagnostic > Packet Capture to investigate.

                      Do you have any other inbound connections?

                      morgensternM 1 Reply Last reply Reply Quote 0
                      • morgensternM Offline
                        morgenstern @viragomann
                        last edited by

                        @viragomann said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                        RFC 1918

                        Nope. It's 188.x.x.x/29

                        1 Reply Last reply Reply Quote 0
                        • morgensternM Offline
                          morgenstern
                          last edited by

                          Okay, I got it!

                          So my simplified rule was too complex! ๐Ÿ™„

                          The source has to be any port from the trusted IP list to HTTPS port on the destination wan IP!

                          SteveITSS 1 Reply Last reply Reply Quote 0
                          • SteveITSS Offline
                            SteveITS Rebel Alliance @morgenstern
                            last edited by

                            @morgenstern said in Cannot access Netgate 6100 over the WAN IP via my usual management NAT rule:

                            any

                            Ah yes the source port is normally random. Easy to read over in a screenshot.

                            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                            Only install packages for your version of pfSense.
                            Upvote ๐Ÿ‘ helpful posts!

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.