<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[New to pfSense - Port Fowarding Issue - Any help would be great]]></title><description><![CDATA[<p dir="auto">Hey guys,</p>
<p dir="auto">OK this is my first post so I will try to include all required information ….</p>
<p dir="auto">I have just installed pfSense on my old PC and I can't for the life of me get port forwarding working. I have spent hours on it, reading through the tutorials, reading forum posts, but unfortunately still can't get it working.</p>
<p dir="auto">==============================================================================================================================</p>
<p dir="auto"><strong>Network Hardware</strong></p>
<p dir="auto">1. Cable internet using a ISP Provided Netgear CG3000 (gutted with stupid ISP firmware)<br />
2. pfSense Box with 3 NICs<br />
3. Netgear GS724T 24 port gigabit switch<br />
4. 5 port unmanaged switch to connect PCs upstairs that connects to the Netgear GS724T downstairs.<br />
5. Workstations in the house</p>
<p dir="auto">Very simple setup.</p>
<p dir="auto">==============================================================================================================================</p>
<p dir="auto"><strong>Network Config</strong></p>
<p dir="auto">Netgear CG3000 Router<br />
IP:192.168.0.1<br />
SN: 255.255.255.0</p>
<p dir="auto">PfSense Box<br />
WAN NIC: ale0<br />
WAN IP: 192.168.0.10 (DHCP assigned from router)<br />
WAN Gateway: 192.168.0.1 (router IP)<br />
LAN NIC: em0<br />
LAN IP: 192.168.2.254<br />
LAN Gateway: no idea, not sure if i even need one?<br />
LAN DHCP Server: 192.168.2.50 - 192.168.2.150<br />
DHCP Reservations<br />
192.168.2.190 - Workstation<br />
192.168.2.191 - Workstation</p>
<p dir="auto">Netgear GS724T Switch<br />
IP: 192.168.2.250<br />
SN: 255.255.255.0<br />
DG: 192.168.2.254 (pfsense LAN interface)</p>
<p dir="auto">Netgear 5 port switch upsatirs: no ip address, just dumb device i guess.</p>
<p dir="auto">I run a cable from LAN1 port on the netgear CG3000 router to the WAN NIC (ale0) on the pfsense box.<br />
I run a cable from the LAN NIC (em0) on the pfSense box to port 1 on the Netgear GS724T switch.<br />
Ports 2,3,4 on the GS724T switch are connected to workstations downstairs.<br />
Port 5 on the GS724T is running upstairs to the 5 port netgear switch, then workstations upstairs are connected into that.</p>
<p dir="auto">Due to the gutted ISP firmware on the CG3000 router, it does not have any way to put it into bridge mode. However it does have a DMZ option.<br />
I have enabled the DMZ option and pointed it to the WAN IP on the pfSense box (192.168.0.10).<br />
I have no firewall rules set on the router, its basically accepting the internet and then going to the DMZ IP I have set.</p>
<p dir="auto">It's my assumption that pointing the router to a DMZ, effectively turns the router into a modem, and all the firewall settings are done on the pfSense box?</p>
<p dir="auto">==============================================================================================================================</p>
<p dir="auto">Browsing the web works fine.</p>
<p dir="auto">So for now all I'm trying to do is forward some ports to specific workstations on the LAN. But when I add the rules they never work. Also I cannot seem to ping anything from the router diagnostic's interface either. Not sure if this is due to the DMZ setting. The only IP I can ping from the router is it's own - 192.168.0.1</p>
<p dir="auto">The firewall logs show the traffic going to the WAN IP 192.168.0.10 for the specific ports, but its getting blocked for some reason.</p>
<p dir="auto">I'm struggling with this one so, any help would be greatly appreciated.</p>
<p dir="auto">I couldn't attach all the screenshots in one post so I have done it in multiple</p>
<p dir="auto">Please let me know if you need anymore information.</p>
<p dir="auto">Cheers</p>
<p dir="auto">Dan</p>
<p dir="auto">![01 - Router DMZ.PNG](/public/<em>imported_attachments</em>/1/01 - Router DMZ.PNG)<br />
![01 - Router DMZ.PNG_thumb](/public/<em>imported_attachments</em>/1/01 - Router DMZ.PNG_thumb)<br />
![02 - Router - No firewall rules.PNG](/public/<em>imported_attachments</em>/1/02 - Router - No firewall rules.PNG)<br />
![02 - Router - No firewall rules.PNG_thumb](/public/<em>imported_attachments</em>/1/02 - Router - No firewall rules.PNG_thumb)<br />
![03 - router - no services enabled.PNG](/public/<em>imported_attachments</em>/1/03 - router - no services enabled.PNG)<br />
![03 - router - no services enabled.PNG_thumb](/public/<em>imported_attachments</em>/1/03 - router - no services enabled.PNG_thumb)<br />
![04 - router - lan settings.PNG](/public/<em>imported_attachments</em>/1/04 - router - lan settings.PNG)<br />
![04 - router - lan settings.PNG_thumb](/public/<em>imported_attachments</em>/1/04 - router - lan settings.PNG_thumb)<br />
![05 - pfsense - dashboard.PNG](/public/<em>imported_attachments</em>/1/05 - pfsense - dashboard.PNG)<br />
![05 - pfsense - dashboard.PNG_thumb](/public/<em>imported_attachments</em>/1/05 - pfsense - dashboard.PNG_thumb)<br />
![06 - pfsense - interfaces assignment.PNG](/public/<em>imported_attachments</em>/1/06 - pfsense - interfaces assignment.PNG)<br />
![06 - pfsense - interfaces assignment.PNG_thumb](/public/<em>imported_attachments</em>/1/06 - pfsense - interfaces assignment.PNG_thumb)</p>
]]></description><link>https://forum.netgate.com/topic/48615/new-to-pfsense-port-fowarding-issue-any-help-would-be-great</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Jul 2026 22:36:41 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/48615.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 16 Sep 2012 09:01:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to New to pfSense - Port Fowarding Issue - Any help would be great on Sun, 16 Sep 2012 14:33:03 GMT]]></title><description><![CDATA[<p dir="auto">No problem dude - what I'm here for.  Common issue really, I would suggest you look to moving to bridge mode on the device from your isp, or get a new device that can be set as just true modem.</p>
<p dir="auto">Double nat is not a ideal setup, sure it can work - but it clearly is not ideal to be sure.</p>
<p dir="auto">Have fun with pfsense - your going to love it!</p>
]]></description><link>https://forum.netgate.com/post/356088</link><guid isPermaLink="true">https://forum.netgate.com/post/356088</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 16 Sep 2012 14:33:03 GMT</pubDate></item><item><title><![CDATA[Reply to New to pfSense - Port Fowarding Issue - Any help would be great on Sun, 16 Sep 2012 14:25:24 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">Don't need to look very far to see what your problem is, See the first rule!! On your WAN!  That is blocking ALL PRIVATE networks.. So yeah you can create a rule below it that allows.  But your first rule says BLOCK, since its to a private IP.  So no other rules are evaluated.</p>
<p dir="auto">Your behind a double nat, so your wan it private ip - so you can not block private ip space.</p>
</blockquote>
<p dir="auto">Hey johnpoz! ….. I have removed that rule and now my NAT rules are applying properly and the traffic is coming through ......</p>
<p dir="auto">Thank you so much for responding and helping me out! :)</p>
]]></description><link>https://forum.netgate.com/post/356087</link><guid isPermaLink="true">https://forum.netgate.com/post/356087</guid><dc:creator><![CDATA[neomanic]]></dc:creator><pubDate>Sun, 16 Sep 2012 14:25:24 GMT</pubDate></item><item><title><![CDATA[Reply to New to pfSense - Port Fowarding Issue - Any help would be great on Sun, 16 Sep 2012 13:03:00 GMT]]></title><description><![CDATA[<p dir="auto">Don't need to look very far to see what your problem is, See the first rule!! On your WAN!  That is blocking ALL PRIVATE networks.. So yeah you can create a rule below it that allows.  But your first rule says BLOCK, since its to a private IP.  So no other rules are evaluated.</p>
<p dir="auto">Your behind a double nat, so your wan it private ip - so you can not block private ip space.</p>
]]></description><link>https://forum.netgate.com/post/356082</link><guid isPermaLink="true">https://forum.netgate.com/post/356082</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sun, 16 Sep 2012 13:03:00 GMT</pubDate></item><item><title><![CDATA[Reply to New to pfSense - Port Fowarding Issue - Any help would be great on Sun, 16 Sep 2012 09:03:09 GMT]]></title><description><![CDATA[<p dir="auto">last screens ….</p>
<p dir="auto">![11 - pfsesnse - firewall rules - WAN.PNG](/public/<em>imported_attachments</em>/1/11 - pfsesnse - firewall rules - WAN.PNG)<br />
![11 - pfsesnse - firewall rules - WAN.PNG_thumb](/public/<em>imported_attachments</em>/1/11 - pfsesnse - firewall rules - WAN.PNG_thumb)<br />
![12 - pfsense - firewall logs - 45678.PNG](/public/<em>imported_attachments</em>/1/12 - pfsense - firewall logs - 45678.PNG)<br />
![12 - pfsense - firewall logs - 45678.PNG_thumb](/public/<em>imported_attachments</em>/1/12 - pfsense - firewall logs - 45678.PNG_thumb)<br />
![13 - pfsense - firewall logs - 45679.PNG](/public/<em>imported_attachments</em>/1/13 - pfsense - firewall logs - 45679.PNG)<br />
![13 - pfsense - firewall logs - 45679.PNG_thumb](/public/<em>imported_attachments</em>/1/13 - pfsense - firewall logs - 45679.PNG_thumb)</p>
]]></description><link>https://forum.netgate.com/post/356073</link><guid isPermaLink="true">https://forum.netgate.com/post/356073</guid><dc:creator><![CDATA[neomanic]]></dc:creator><pubDate>Sun, 16 Sep 2012 09:03:09 GMT</pubDate></item><item><title><![CDATA[Reply to New to pfSense - Port Fowarding Issue - Any help would be great on Sun, 16 Sep 2012 09:02:41 GMT]]></title><description><![CDATA[<p dir="auto">more screens…..</p>
<p dir="auto">![07 - pfsense - WAN interface.PNG](/public/<em>imported_attachments</em>/1/07 - pfsense - WAN interface.PNG)<br />
![07 - pfsense - WAN interface.PNG_thumb](/public/<em>imported_attachments</em>/1/07 - pfsense - WAN interface.PNG_thumb)<br />
![08 - pfsense - LAN interface.PNG](/public/<em>imported_attachments</em>/1/08 - pfsense - LAN interface.PNG)<br />
![08 - pfsense - LAN interface.PNG_thumb](/public/<em>imported_attachments</em>/1/08 - pfsense - LAN interface.PNG_thumb)<br />
![09 - pfsesnse - NAT rules.PNG](/public/<em>imported_attachments</em>/1/09 - pfsesnse - NAT rules.PNG)<br />
![09 - pfsesnse - NAT rules.PNG_thumb](/public/<em>imported_attachments</em>/1/09 - pfsesnse - NAT rules.PNG_thumb)<br />
![10 - pfsesnse - firewall rules - LAN.PNG](/public/<em>imported_attachments</em>/1/10 - pfsesnse - firewall rules - LAN.PNG)<br />
![10 - pfsesnse - firewall rules - LAN.PNG_thumb](/public/<em>imported_attachments</em>/1/10 - pfsesnse - firewall rules - LAN.PNG_thumb)</p>
]]></description><link>https://forum.netgate.com/post/356072</link><guid isPermaLink="true">https://forum.netgate.com/post/356072</guid><dc:creator><![CDATA[neomanic]]></dc:creator><pubDate>Sun, 16 Sep 2012 09:02:41 GMT</pubDate></item></channel></rss>