Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Cloning a NAT Rule and modifying it, failed to forward traffic. Deleted and recreate with same paramaters and it worked

    Scheduled Pinned Locked Moved NAT
    4 Posts 2 Posters 161 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      HawaiianHopeOrg
      last edited by

      HI ! First Post here.
      We been using pfSense for about 5 years now, We also install it at various non profit client sites so we have about a dozen installations running right now.
      I may have found a bug.
      In this particular location, we have :

      • pfSense installed on physical hardware
      • 2.8.1-RELEASE (amd64) built on Wed Nov 26 11:12:00 HST 2025 FreeBSD 15.0-CURRENT
      • A WAN address and multiple Virtual WAN IP's
      • Multiple NAT port forwarding rules to various internal LAN IPs,- some set up using Aliases.

      Yesterday I set up a new VM on a server cluster, a clone of another working VM.
      I then CLONED one of the NAT rules for the same cloned VM.
      I then Modified that NAT rule with all of the necessary settings (changed the external Virtual IP the rule is looking at, changed the internal port it is forwarding to)
      Hit Save.

      No matter what I did, I could not get data to forward to that server. I went back and tinkered with it like 14 times over 3 hours, thinking maybe I got the wrong alias, or the wrong ports, or the wrong IP address. Nope, all correct and looking good.

      So, then I set up a test on the local network to access that VM and log a user account into it. It worked instantly telling me it is a firewall issue.

      So I go back to pfSense and look at the NAT settings more, change order, etc.
      Nothing I did mattered.

      So, I decided to delete the NAT rule, and key it from scratch. It worked immediately as soon as I hit submit and applied changes.

      So now it is working as expected. But all of this leads me to believe that cloning that NAT rule somehow was stuck and internal data was never updated to get the actual port forwarding to work. AS soon as i deleted it and redid it from scratch with eh exact same parameters, it worked.

      So, anyone else experience something like this ? Is this a potential bug ? I have not tried to replicate the issue yet but I do have to set up another couple of VMs of the same server, so I can try it some more.

      THANK S FOR pfSense ! We LOVE it !

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @HawaiianHopeOrg
        last edited by

        @HawaiianHopeOrg Can you try in 2.9?

        So it was same port, new WAN IP (VIP)?

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote ๐Ÿ‘ helpful posts!

        H 1 Reply Last reply Reply Quote 0
        • H Offline
          HawaiianHopeOrg @SteveITS
          last edited by

          @SteveITS
          Sorry, Are you asking what I was moving from, moving to ?
          or if me hard coding it changed it ?
          Or when I cloned it what I changed in the initial clone ?

          SteveITSS 1 Reply Last reply Reply Quote 0
          • SteveITSS Offline
            SteveITS Rebel Alliance @HawaiianHopeOrg
            last edited by

            @HawaiianHopeOrg well I thought I pasted a link...see

            https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html#rules-nat:~:text=Same%20port%20forward%20on%20multiple%20WANs
            ?

            Doesn't seem like it breaks things if I read it right yesterday...?

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote ๐Ÿ‘ helpful posts!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
            Privacy Policy · Cookie Policy