Cloning a NAT Rule and modifying it, failed to forward traffic. Deleted and recreate with same paramaters and it worked
-
HI ! First Post here.
We been using pfSense for about 5 years now, We also install it at various non profit client sites so we have about a dozen installations running right now.
I may have found a bug.
In this particular location, we have :- pfSense installed on physical hardware
- 2.8.1-RELEASE (amd64) built on Wed Nov 26 11:12:00 HST 2025 FreeBSD 15.0-CURRENT
- A WAN address and multiple Virtual WAN IP's
- Multiple NAT port forwarding rules to various internal LAN IPs,- some set up using Aliases.
Yesterday I set up a new VM on a server cluster, a clone of another working VM.
I then CLONED one of the NAT rules for the same cloned VM.
I then Modified that NAT rule with all of the necessary settings (changed the external Virtual IP the rule is looking at, changed the internal port it is forwarding to)
Hit Save.No matter what I did, I could not get data to forward to that server. I went back and tinkered with it like 14 times over 3 hours, thinking maybe I got the wrong alias, or the wrong ports, or the wrong IP address. Nope, all correct and looking good.
So, then I set up a test on the local network to access that VM and log a user account into it. It worked instantly telling me it is a firewall issue.
So I go back to pfSense and look at the NAT settings more, change order, etc.
Nothing I did mattered.So, I decided to delete the NAT rule, and key it from scratch. It worked immediately as soon as I hit submit and applied changes.
So now it is working as expected. But all of this leads me to believe that cloning that NAT rule somehow was stuck and internal data was never updated to get the actual port forwarding to work. AS soon as i deleted it and redid it from scratch with eh exact same parameters, it worked.
So, anyone else experience something like this ? Is this a potential bug ? I have not tried to replicate the issue yet but I do have to set up another couple of VMs of the same server, so I can try it some more.
THANK S FOR pfSense ! We LOVE it !
-
@HawaiianHopeOrg Can you try in 2.9?
So it was same port, new WAN IP (VIP)?
-
@SteveITS
Sorry, Are you asking what I was moving from, moving to ?
or if me hard coding it changed it ?
Or when I cloned it what I changed in the initial clone ? -
@HawaiianHopeOrg well I thought I pasted a link...see
Doesn't seem like it breaks things if I read it right yesterday...?
Privacy Policy · Cookie Policy