Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot access internal web server from outside

    Scheduled Pinned Locked Moved NAT
    7 Posts 4 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wetfish
      last edited by

      I have just installed and configured 2.0.1-RELEASE (amd64). It's a basic installation with NO packages.

      I created an NAT port forward from my WAN to my internal web server on port 80.

      However, I cannot access the web server from the internet. I can access it from my internal network.

      I am also SURE that my ISP is not blocking port 80 as I just used the same connection to host my web server before I installed the firewall.

      There's nothing showing in the firewall logs either.

      I have included my config as images.

      Can please someone help as I am lost.

      Thanks
      advanced.JPG
      advanced.JPG_thumb
      portforward.JPG
      portforward.JPG_thumb
      wanrule.JPG
      wanrule.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        Go to system/advanced:

        Under "webConfigurator"  set your pfsense box to a different TCP port than 80…  (Then remember it... )

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • marcellocM
          marcelloc
          last edited by

          And also change protocol to https. ;)

          8443 maybe easy to remember.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • W
            wetfish
            last edited by

            Hi,
            Thanks guys for the prompt reply.

            However, unfortunately, it did not work.

            I changed the webconfigurator to https on a different port.
            I also deleted all rules and recreated them (see attached pics).

            I don't know what I'm missing.

            If you have any ideas, you are more then welcome to help.
            Thanks

            Advanced.jpg
            Advanced.jpg_thumb
            ![firewall lan.jpg](/public/imported_attachments/1/firewall lan.jpg)
            ![firewall lan.jpg_thumb](/public/imported_attachments/1/firewall lan.jpg_thumb)
            ![firewall wan.jpg](/public/imported_attachments/1/firewall wan.jpg)
            ![firewall wan.jpg_thumb](/public/imported_attachments/1/firewall wan.jpg_thumb)
            NAT.jpg
            NAT.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • marcellocM
              marcelloc
              last edited by

              use tcpdump on console to see these port 80 packages arriving.

              If you have a dsl router, configure pfsense ip as a dmz server on modem gui.

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by

                Port forwards override your web interface port, doesn't matter whether you change that. Go through the steps here:
                http://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

                1 Reply Last reply Reply Quote 0
                • W
                  wetfish
                  last edited by

                  Thanks guys for your help.

                  I managed to NAT port 80 successfully after changing the admin port to a port other than 80 and used SSL on a different port as well.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.