• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can't connect to game server on my network by public IP

Scheduled Pinned Locked Moved Gaming
10 Posts 6 Posters 17.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Telex
    last edited by Jul 29, 2011, 2:30 AM

    I have a rather strange issue that is just a major nuisance to me.  I have a game server for the multiplayer game Halo PC on a subnet (172.16.0.0/24) that is separate from the subnet of my home computers (10.0.0.0/24).  The game server is running on port 2001 and the private IP is 172.16.0.10.  Any player on the internet is able to connect to the server by entering my public IP address (or by joining from the server list), except for me.  However, I can join by the server's LAN address.

    This game seems to be the only thing I have an issue with.  I also run a Minecraft server on the same physical box, and I can connect to the server by public IP with no problem.  NAT reflection is enabled for the Halo server, just like with the Minecraft server, so I don’t know where else to troubleshoot this problem.  However, I’m sure this is a NAT reflection issue.  I'm not sure if it has anything to do with Halo being UDP and Minecraft being TCP.

    The reason this is such a big issue for me is because I’m unable to join my own servers from the in-game server list.  With my old cheap SOHO router, I was able to connect to the server by public IP from within my own network, so I’m sure it has to be possible with pfSense and a few tweaks.

    I have some screenshots below of the outbound NAT rule, NAT forwarding rule, and a side-by-side comparison of Halo vs. Minecraft states.  If you need any more info, or even remote access, I'll be glad to provide.

    NAT Outbound:

    NAT Port Forwarding:

    Here’s what happens when someone connects to the Halo server from outside my network:

    And here’s what happens when I try to join from inside my own network:

    And me joining Minecraft from inside my own network:

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Aug 1, 2011, 6:28 PM

      Last I knew, NAT reflection was not (and has never) worked properly for UDP.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • T
        Telex
        last edited by Aug 2, 2011, 5:12 PM

        So, am I pretty much out of luck here?  I read about DNS forwarders helping in similar scenarios, except that won't work here since the server lists work by IP address, not FQDN's.  If there's anything else I can try, please let me know.

        1 Reply Last reply Reply Quote 0
        • M
          Metu69salemi
          last edited by Aug 2, 2011, 8:27 PM

          Try to create local fqdn and use that internally, if that works

          1 Reply Last reply Reply Quote 0
          • T
            Telex
            last edited by Aug 3, 2011, 4:28 AM

            I thought that was essentially the same as the DNS forwarder custom records, which is pointless for my configuration since the server list references each server directly by IP address, not a FQDN.

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by Aug 9, 2011, 10:45 AM

              Hey Guys,

              –--NOT SURE HOW THIS WORKS----

              I had weird kind of idea.. Can you try static routing+rules

              1. Create a new route for that public ip
              1.1 Create a new gateway use an internal nic
              2. Create a rule: source: gaming client, destination: servers public ip and advanced option: use new gateway

              ----/NOT SURE HOW THIS WORKS----

              It might get you there, but it can also break your routing anywhere else

              1 Reply Last reply Reply Quote 0
              • B
                babbler
                last edited by Nov 14, 2011, 5:44 PM

                I agree with Telex. UDP NAT reflection works on the cheapest router/nat device. It's a shame it does not work on pfsense.
                Maybe the fault is in us, because there is no ticket for this error.

                If it helps to somebody, the packet arrives to the reflected ip/port (the server), but the response not gets back to the client.

                1 Reply Last reply Reply Quote 0
                • D
                  dhatz
                  last edited by Nov 16, 2011, 8:18 PM

                  There seem to be several old threads in this forum about implementing UDP NAT Reflection in pfsense and in fact there is relevant section in filter.inc (search for 19000)

                  1 Reply Last reply Reply Quote 0
                  • B
                    babbler
                    last edited by Nov 17, 2011, 6:30 AM

                    You are rigth. It seems it's fully implemented. An in fact it's working in one way. The problem is with the reply packets.

                    1 Reply Last reply Reply Quote 0
                    • F
                      francisuk22
                      last edited by May 20, 2012, 7:39 PM

                      http://www.youtube.com/watch?v=BB6fdyVNlVg

                      2.0.2-RELEASE (amd64) - Dell OptiPlex GX520 SFF @ Intel P4 HT 3.0GHz
                      Cisco SR224 24-port Switch (4 PCs, 1 Wireless AP, 2 Consoles)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received