Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    port forward doesnt work

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 455 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      asiawatcher
      last edited by asiawatcher

      i want to put a simple port forward to access the web interface of my nas from my public ip

      here is what i did which fails. any clues ? I think that's very simple and should have worked as I done port forward many times before with other routers

      pf1.png pf2.png pf3.png
      Thanks

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @asiawatcher
        last edited by

        @asiawatcher did you find https://docs.netgate.com/pfsense/en/latest/troubleshooting/nat-port-forwards.html ?

        Does the firewall on the NAS allow connections from outside its subnet?

        Btw that second rule on your WAN allows anyone to access pfSense via http or ssh…note the 19 open connections there.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        A 2 Replies Last reply Reply Quote 0
        • A
          asiawatcher @SteveITS
          last edited by

          @SteveITS I'll go to that link and read it yes nas has firewall disabled i have it all open for testing

          so what do you think is wrong ?

          1 Reply Last reply Reply Quote 0
          • A
            asiawatcher @SteveITS
            last edited by

            @SteveITS read all that i also disabled upnp on my isp router, nothing

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @asiawatcher
              last edited by

              @asiawatcher if there’s an ISP router providing NAT it would need to forward the port to pfSense. (Presumably so since something is being forwarded allowing connections on WAN).

              If you are testing from behind pfSense you need NAT reflection enabled for that rule.
              https://docs.netgate.com/pfsense/en/latest/nat/reflection.html

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              A 1 Reply Last reply Reply Quote 0
              • A
                asiawatcher @SteveITS
                last edited by asiawatcher

                @SteveITS ISP router has pfsense on dmz so everything is open

                I'm trying from outside via anydesk

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @asiawatcher
                  last edited by johnpoz

                  @asiawatcher step one is actually validate traffic gets to pfsense wan, pfsense can not forward what it never sees.

                  So go to like can you see me . org - test to this port 5000 while you sniff (packet capture) on the wan - do you actually see the traffic get there?

                  port.jpg

                  Maybe your behind a cgnat? If you do not see the traffic hit your pfsense wan, then it can never forward it. If you see it, then sniff on your lan when you do the same test - do you see it send it on to this 192.168.100.200 box?

                  Possible this 100.200 box is running its own firewall, or not even listening on that port, or maybe not using pfsense as gateway. But until you actually validate pfsense sees the traffic on the wan.. Maybe your rules are wrong, mabye the IP your forwarding to is wrong, etc. etc..

                  But first step is to make sure pfsense actually sees the traffic your wanting to forward, otherwise your just going to be spinning your wheels and it would never work..

                  edit: here you can see my port forward I created, but my box isn't listening on that port - but pfsense would still send it on. Via packet capture on my lan interface when doing the can you see me test.

                  portforward.jpg

                  So pfsense did what I told it too - but the box didn't answer, so the problem is not with the port forward. You would also notice the counter went up on my firewall rule showing that it allowed traffic.

                  counter.jpg

                  But first step in troubleshooting port forwards should be to actually validate traffic gets to pfsense to port forward.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.