New guy trying to get NAT/port forwarding to work

  • Hi.  First post.  Need assist.
    I have not been able to get my below scenario to work.  Have tried ipcop, m0n0wall, pfsense.  PFsense seems by far the most complete firewall, but still no luck.

    Checked the RFC959 violation box.
    I am merely trying to forward some ports from over to
    Opened all ports (1-65535) out of frustration at just getting the few I really wanted.
    Didn't do anything with the Virtual IP's and CARP menu - not sure of what it really means yet.
    This seems to be a really no-brainer configuration but not working for me.

    WireShark on WinXP with "host and host" gives nothing.
    pfsense firewall log shows this (test with ftp) - doesn't seem to be forwarded.
    (passed) Jan 6 19:50:40 WAN UDP
    (passed) Jan 6 19:44:09 WAN TCP:S

    Please, anyone know what I am missing.  I use at home a Juniper Netscreen NS5GT so am not a total novice with all this, but I am baffled.

    Thanks much,


    PC Linux client on  => pfsense (WAN (LAN to PC WinXP on

    PCLinux Client (single interface)
    netstat -r:
    Dest  *
    ifconfig shows up

    pfsense firewall

    re0 interface
    re1 interface

    NAT:    WAN  TCP/UDP  1 - 65535  target(aliased to (ext.: any) 1 - 65535
    Rule:  TCP/UDP  *  *  target  1 - 65535  *

    Windows XP (ipconfig /all output)
    IP Address. . . . . . . . . . . . :
    Subnet Mask . . . . . . . . . . . :
    Default Gateway . . . . . . . . . :

  • Some more info.

    On WinXP, I can ping pfsense at

    On pfsense I can ping WinXP and get normal ping response.

    I cannot ping pfsense from my linux
    On pfsense if I ping any address on 20.20.20.x network, I get this weird response:

    pfhacom:~#  ping
    PING ( 56 data bytes
    36 bytes from pfhacom.local ( Time to live exceeded
    Vr HL TOS  Len  ID Flg  off TTL Pro  cks      Src      Dst
    4  5  00 5400 b029  0 0000  01  01 3eff


    baffled Jim

  • OK.  that was dumb.  the ping to any 20.20.20.x address was actually not responded.  Just all that info telling me about it