NAT port forwarding overlaps



  • Hi

    I am trying to forward NAT port 5060 to specyfic IP and I have a problem becasue:

    •The external port range overlaps with an existing entry.

    5060 is already nated to the IP of Trixbox. IS then not posible to forward the same ports to different IPs?

    MST



  • @mst:

    Hi

    I am trying to forward NAT port 5060 to specyfic IP and I have a problem becasue:

    •The external port range overlaps with an existing entry.

    5060 is already nated to the IP of Trixbox. IS then not posible to forward the same ports to different IPs?

    MST

    It is not possible - how would pfsense know which IP to forward traffic on that port to?



  • Hmmm I am confused or I was wrong.

    In 1.2.3 RC1 I was able to do NAT port forwarding to different IPS on the LAN. WHy it is not possible in 2.0? The same port 5060 I was able to forward to
    Trixbox and IP phones. Please let me know if there is something that I don't know. This work in other software firewalls. I don't know I think it was misunderstanding.

    Regards,

    MST



  • I am sorry my bed you are right althornin. Then how I can resolve the problem with the same port and multiple IPs.

    In Cisco ASA it is called SIP fixup and you can froward the same port to multiple IPS.

    Please advice.

    Thank you



  • If its VOIP port forwarding you want then the Freeswitch package might be what you are looking for.



  • PLease take a look at a picture. There are 2 times that 5060 is forwarded to two different IPS in the same LAN. So , it is a bug? It is 1.2.3 RC1 stable release.




  • Think of port forwarding as a freeway offramp. Your forcing all port 5060 traffic to the first IP.

    The second occurrence being further down the list should be ignored and not work.

    The RTP ports overlap also.  This can not work by design.



  • Is it not possible to implement a virtual coin toss to help deal with these sort of issues ??

    Puge


Locked