<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[pfsense ce 2.7.2 configured with port forwarding, packet drops randomly (pfsenseplus looks like work)]]></title><description><![CDATA[<p dir="auto">I configured port forwarding rules for our application, to allow the client access this application, we need allow 3 tcp and 4 udp ports<br />
<img src="/assets/uploads/files/1722339910311-b69f5f5e-a936-4f5a-8bc8-3b54e93eebde-image-resized.png" alt="b69f5f5e-a936-4f5a-8bc8-3b54e93eebde-image.png" class=" img-fluid img-markdown" /><br />
then we lauched the connections, but most time it will be failed to connect only few of chance we can connect through.<br />
I capture network logs on pfsense and client at the same time, from logs on client side i found many retransmit and cause the connection stopped, while i checked logs on pfsense, i found syn/syc+ack, but looks like tcp packet didn't hit on wan interface<br />
<img src="/assets/uploads/files/1722340160848-6bdc63c5-3d62-4aa2-8010-01c565ba1b7a-image-resized.png" alt="6bdc63c5-3d62-4aa2-8010-01c565ba1b7a-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">i did lots of tuning, such as re-install pfsense ce, enlarge the spec(cpu/mem), tuning parameters, but the same not work</p>
<p dir="auto">we did the same on pfsense plus (23.09), looks like it works on pfsense plus.</p>
<p dir="auto">so my question is:<br />
1、is it possible known issue/bug for this case?<br />
2、how should i trouble shoot further for this kind of issue; in another word, how could i check confirm where and how  the packet drop?</p>
<p dir="auto">Thanks much for your help!</p>
]]></description><link>https://forum.netgate.com/topic/189405/pfsense-ce-2-7-2-configured-with-port-forwarding-packet-drops-randomly-pfsenseplus-looks-like-work</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 06:05:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/189405.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 30 Jul 2024 11:53:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to pfsense ce 2.7.2 configured with port forwarding, packet drops randomly (pfsenseplus looks like work) on Thu, 08 Aug 2024 07:52:59 GMT]]></title><description><![CDATA[<p dir="auto">i finally found the cause, i changed the 'Filter Rule association' from 'pass' to other, i then works<br />
<img src="/assets/uploads/files/1723103470124-c64cd004-70ad-491e-b301-eafe18d333f1-image-resized.png" alt="c64cd004-70ad-491e-b301-eafe18d333f1-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">but the thing is we have default gateway and even i allow all in firewall rule, but nat with filter rule association 'pass', nat still not forward the traffic; looks like it's the bug of pfsense<br />
<img src="/assets/uploads/files/1723103505590-3375e8e7-e1fc-4306-8f6a-80cc70841df5-image.png" alt="3375e8e7-e1fc-4306-8f6a-80cc70841df5-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1179863</link><guid isPermaLink="true">https://forum.netgate.com/post/1179863</guid><dc:creator><![CDATA[allenlwli]]></dc:creator><pubDate>Thu, 08 Aug 2024 07:52:59 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense ce 2.7.2 configured with port forwarding, packet drops randomly (pfsenseplus looks like work) on Thu, 01 Aug 2024 02:59:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
thank you much for your help<br />
For NAT reflection, even we tried to use options like system default/disbaled/pure NAT, the same not working</p>
<p dir="auto">The thing is if I switch to use pfsense plus (23.09), which is under same subnet as pfsense CE, then the  connectivity will be good;<br />
I am a little bit suspect there is ongoing bug with pfsense CE</p>
]]></description><link>https://forum.netgate.com/post/1178907</link><guid isPermaLink="true">https://forum.netgate.com/post/1178907</guid><dc:creator><![CDATA[allenlwli]]></dc:creator><pubDate>Thu, 01 Aug 2024 02:59:22 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense ce 2.7.2 configured with port forwarding, packet drops randomly (pfsenseplus looks like work) on Tue, 30 Jul 2024 16:50:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/allenlwli">@<bdi>allenlwli</bdi></a> said in <a href="/post/1178682">pfsense ce 2.7.2 configured with port forwarding, packet drops randomly (pfsenseplus looks like work)</a>:</p>
<blockquote>
<p dir="auto">but looks like tcp packet didn't hit on wan interface</p>
</blockquote>
<p dir="auto">If packets don't hit = arrive (right ?) at the pfSense WAN gate, your pfSense issues is solved, as the issue is upstream.</p>
<p dir="auto">Not sure what this is :</p>
<p dir="auto"><img src="/assets/uploads/files/1722358148879-afb3c08a-f61c-4236-bcbb-6bc3f24c334d-image.png" alt="afb3c08a-f61c-4236-bcbb-6bc3f24c334d-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">but for classic port and addresses NATing I never hat to take that setting from 'default'.</p>
]]></description><link>https://forum.netgate.com/post/1178732</link><guid isPermaLink="true">https://forum.netgate.com/post/1178732</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 30 Jul 2024 16:50:42 GMT</pubDate></item></channel></rss>