<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I upgraded our Netgate 7100 to Pfsense Beta 25.03. However, port forwarding stopped working. Any idea how to resolve this.</p>
<p dir="auto">Sam</p>
]]></description><link>https://forum.netgate.com/topic/197680/port-forwarding-not-working-after-upgrade-to-beta-25-03</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 09:24:27 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/197680.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 03 Jun 2025 10:55:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 16:05:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1217840">PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03</a>:</p>
<blockquote>
<p dir="auto">Anyway, very soon we can ditch IPv4 and Natting and things become easy for everybody</p>
</blockquote>
<p dir="auto">Yeah soon ;) they have been saying that for 20+ years already.. Soon ;)</p>
]]></description><link>https://forum.netgate.com/post/1217845</link><guid isPermaLink="true">https://forum.netgate.com/post/1217845</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 12 Jun 2025 16:05:59 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 16:00:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/1217830">PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03</a>:</p>
<blockquote>
<p dir="auto">but there is quic now, and it is possible to run http and https over UDP</p>
</blockquote>
<p dir="auto">So, first : Normally I would agree with you <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
But if some one would set up an apache2 or nginx on its LAN using https, <strong>quic</strong> then this person can't have problems with ancient stuff like "natting" a port.<br />
Right ?<br />
( I do have this feeling that the pfSense documentation isn't always clear about things. That's why I love the - old, true, but still very valid - Youtube videos on the Netgate channel )</p>
<p dir="auto">Port natting (= patting), on my ISP router, pfSense, or a high end Cisco or any other TPlink /DLink wallmart device out there : it's all the same ...</p>
<p dir="auto">Anyway, very soon we can ditch IPv4 and Natting and things become easy for everybody .... <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
]]></description><link>https://forum.netgate.com/post/1217840</link><guid isPermaLink="true">https://forum.netgate.com/post/1217840</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 12 Jun 2025 16:00:17 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 15:19:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1217822">PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03</a>:</p>
<blockquote>
<p dir="auto">Btw : Web server traffic is TCP only.</p>
</blockquote>
<p dir="auto">Normally I would agree with you - but there is quic now, and it is possible to run http and https over UDP.</p>
<p dir="auto">But highly unlikely in the case of someone running something behind pfsense.</p>
]]></description><link>https://forum.netgate.com/post/1217830</link><guid isPermaLink="true">https://forum.netgate.com/post/1217830</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 12 Jun 2025 15:19:43 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 14:58:58 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/samweli">@<bdi>samweli</bdi></a></p>
<p dir="auto">So traffic should come in into the WAN IP, with as destination the WAN IP.<br />
Your packet capture, you were using the WAN interface, right ? an not LAN ?</p>
<p dir="auto">From there on, the WAN IPv4 and the destination port = 80, matches with a WAN firewall rule, the firewall rule that belongs to the NAT rule. If the two match,n then the traffic is mapped to the LAN network, the IP 172.16.111.15. same port.</p>
<p dir="auto">Btw : Web server traffic is TCP only.</p>
<p dir="auto">This :</p>
<p dir="auto"><img src="/assets/uploads/files/1749739887808-7fa6e2e3-9599-4685-96cc-fd91085a0edf-image.png" alt="7fa6e2e3-9599-4685-96cc-fd91085a0edf-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">You've set a gateway ?<br />
Please read [Port Forwarding](https://docs.netgate.com/pfsense/en/latest/nat/port-forwards.html¶ one more time.</p>
]]></description><link>https://forum.netgate.com/post/1217822</link><guid isPermaLink="true">https://forum.netgate.com/post/1217822</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 12 Jun 2025 14:58:58 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 14:46:10 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> You are right. 172.16.111.15 is a LAN host on 172.16.0.0/16 network on the LAN side. The WAN IP is sitting on the ZAMTELINTERNET interface</p>
]]></description><link>https://forum.netgate.com/post/1217815</link><guid isPermaLink="true">https://forum.netgate.com/post/1217815</guid><dc:creator><![CDATA[samweli]]></dc:creator><pubDate>Thu, 12 Jun 2025 14:46:10 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 14:06:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/samweli">@<bdi>samweli</bdi></a> said in <a href="/post/1217799">PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03</a>:</p>
<blockquote>
<p dir="auto">172.16.111.15</p>
</blockquote>
<p dir="auto">Oops.<br />
172.16.x.y is RFC1918.</p>
<p dir="auto">Knowing that you can not find RFC1918 out there on the internet.<br />
RFC1918can't be routed on the Internet.<br />
That means that if an RFC1918 IP like 192.168.1.1 or your 172.16.111.15 passes trough any router out there, that ones that are part of the 'Internet', it's dropped right away.</p>
<p dir="auto">This makes me wonder :</p>
<pre><code>14:39:02.026573 IP 45.215.255.224.40542 &gt; 172.16.111.15.80: tcp 0
14:39:07.897087 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0
14:39:08.916557 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0
14:39:09.926632 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0
14:39:10.926291 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0
</code></pre>
<p dir="auto">How did you obtain these results ?<br />
I presume now that 172.16.111.x is your pfSense LAN network, and not your WAN.<br />
Or is 172.16.111.15 your pfSense WAN IP and you have a router in front of your pfSense ? In that case, it would be ok.</p>
<p dir="auto">edit :</p>
<p dir="auto">Noop.<br />
<img src="/assets/uploads/files/1749737143184-a7054e18-1d87-4fad-9ba9-98092f0e98e5-image.png" alt="a7054e18-1d87-4fad-9ba9-98092f0e98e5-image.png" class=" img-fluid img-markdown" /><br />
so 172.16.111.15 is your pfSense LAN ? !</p>
]]></description><link>https://forum.netgate.com/post/1217805</link><guid isPermaLink="true">https://forum.netgate.com/post/1217805</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 12 Jun 2025 14:06:40 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 13:37:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
<img src="/assets/uploads/files/1749735284386-ab771e3f-fd34-497b-90a0-3fcb8a97f347-image.png" alt="ab771e3f-fd34-497b-90a0-3fcb8a97f347-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1749735416446-876861c7-fb44-476b-820c-ec4b18c68233-image.png" alt="876861c7-fb44-476b-820c-ec4b18c68233-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1217802</link><guid isPermaLink="true">https://forum.netgate.com/post/1217802</guid><dc:creator><![CDATA[samweli]]></dc:creator><pubDate>Thu, 12 Jun 2025 13:37:25 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 13:22:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a></p>
<p dir="auto">Thanx once more,</p>
<p dir="auto">45.215.255.224 is the device outside the network tring to access 172.16.111.15 which is the web server inside the betwork.</p>
]]></description><link>https://forum.netgate.com/post/1217799</link><guid isPermaLink="true">https://forum.netgate.com/post/1217799</guid><dc:creator><![CDATA[samweli]]></dc:creator><pubDate>Thu, 12 Jun 2025 13:22:26 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 13:04:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/samweli">@<bdi>samweli</bdi></a></p>
<p dir="auto">As I don't know who 45.215.255.224 is, neither 172.16.111.15 i'll have to presume a lot.</p>
<p dir="auto">I see a destination port 80 : that's an old web or 'http' server.<br />
If - you tell me - 172.16.111.15 is your pfSense WAN, and 45.215.255.224 is the device with a web browser, then you've shown that the intended web traffic arrives at your pfSense WAN  interface.</p>
<p dir="auto">Now : can show your NAT rule (and the auto created WAN firewall rule) ?</p>
<p dir="auto">edit :<br />
I've just installed the latest 5.03 beta, "25.03.b.20250610.1659", and it works well.</p>
]]></description><link>https://forum.netgate.com/post/1217792</link><guid isPermaLink="true">https://forum.netgate.com/post/1217792</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 12 Jun 2025 13:04:27 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Thu, 12 Jun 2025 12:41:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> Hi, Thank you so much for your feedback.</p>
<p dir="auto">I have done that and these are the results.</p>
<p dir="auto">14:39:02.026573 IP 45.215.255.224.40542 &gt; 172.16.111.15.80: tcp 0<br />
14:39:07.897087 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0<br />
14:39:08.916557 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0<br />
14:39:09.926632 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0<br />
14:39:10.926291 IP 45.215.255.224.29311 &gt; 172.16.111.15.80: tcp 0</p>
]]></description><link>https://forum.netgate.com/post/1217788</link><guid isPermaLink="true">https://forum.netgate.com/post/1217788</guid><dc:creator><![CDATA[samweli]]></dc:creator><pubDate>Thu, 12 Jun 2025 12:41:32 GMT</pubDate></item><item><title><![CDATA[Reply to PORT FORWARDING NOT WORKING AFTER UPGRADE TO BETA 25.03 on Tue, 03 Jun 2025 13:06:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/samweli">@<bdi>samweli</bdi></a></p>
<p dir="auto">The good news : nothing changed, so there shouldn't be any issues.<br />
For example, I've several NAT rules in place, I use the latest 25.03 Beta version "25.03.b.20250515.1415".</p>
<p dir="auto">Best guess : check if traffic reaches your WAN ?<br />
Use the packet capture ( Diagnostics &gt; Packet Capture ), select the WAN, specify the correct "destination port" and NAT protocol, UDP or TCP and start the capture.<br />
Now you can see if traffic that was natted before, even reaches pfSense.</p>
<p dir="auto">Another check : the device you NAT to (some device on a LAN ?) still use the same IPv4 ?</p>
]]></description><link>https://forum.netgate.com/post/1216506</link><guid isPermaLink="true">https://forum.netgate.com/post/1216506</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Tue, 03 Jun 2025 13:06:00 GMT</pubDate></item></channel></rss>