Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Unable to Create Firewall Rule with Port Alias.

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 2 Posters 189 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      Witchboard
      last edited by

      I'm trying to redirect a port over VPN. I created an alias with the port I'm wanting, but when I try and configure a firewall rule with it, it doesn't autocomplete like my other aliases. When I manually type it I get a message that it is not a valid IP address or alias.

      I don't have these issues with IP aliases. Is it not possible to create a firewall rule for a port?

      1 Reply Last reply Reply Quote 0
      • tinfoilmattT Offline
        tinfoilmatt LAYER 8
        last edited by

        Screencaps?

        block out log on { ix0 } inet from any to any
        block out log on { ix0 } inet6 from any to any

        1 Reply Last reply Reply Quote 0
        • W Offline
          Witchboard
          last edited by

          Sure thing!

          7ff1e972-f9dd-4dc5-83c7-895e4365e4f7-image.png

          6db3bf09-3f16-4901-b037-a1a486554208-image.png

          tinfoilmattT 1 Reply Last reply Reply Quote 0
          • tinfoilmattT Offline
            tinfoilmatt LAYER 8 @Witchboard
            last edited by

            You're entering your port alias into the source address field. Change the protocol from "Any" to "TCP", "UDP", or "TCP/UDP" and you'll see a blue "Display Advanced" button appear, which will allow you to specify source port via alias or otherwise.

            d313159b-8a73-4111-b192-46ff49aba99f-image.png

            block out log on { ix0 } inet from any to any
            block out log on { ix0 } inet6 from any to any

            1 Reply Last reply Reply Quote 0
            • W Offline
              Witchboard
              last edited by

              So, creating an alias is not necessary if I want to create a rule for a specific port? I only need to create an alias with the systems I'm wanting to use that port with? Sorry if I'm not understanding.

              tinfoilmattT 1 Reply Last reply Reply Quote 0
              • tinfoilmattT Offline
                tinfoilmatt LAYER 8 @Witchboard
                last edited by

                So, creating an alias is not necessary if I want to create a rule for a specific port

                That's correct. If the rule only contemplates a single port, here 55930—then you need only enter 55930 in the correct field.

                block out log on { ix0 } inet from any to any
                block out log on { ix0 } inet6 from any to any

                W 1 Reply Last reply Reply Quote 0
                • W Offline
                  Witchboard @tinfoilmatt
                  last edited by

                  @tinfoilmatt

                  Thank you for the help.

                  tinfoilmattT 1 Reply Last reply Reply Quote 0
                  • tinfoilmattT Offline
                    tinfoilmatt LAYER 8 @Witchboard
                    last edited by tinfoilmatt

                    Shot in the dark, but you're probably also needing 55930 as the destination port, not the source port.

                    You're welcome. We'll all be here if follow-up is needed as you make more progress.

                    block out log on { ix0 } inet from any to any
                    block out log on { ix0 } inet6 from any to any

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                    Privacy Policy · Cookie Policy