Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN -> LAN ssh problem

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 5.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      core
      last edited by

      Hi everyone,

      this is not exactly an openSSH problem, but a generic ssh one. Nonetheless, I hope this is the correct board for such a question.

      I switched to pfSense from a homebrew packet filter for our small network. Previously I could connect from an external machine to an internal one using ssh. Using pfSense I face the problem that the connection passes through the firewall (a matching rule for port 22 was created) and reaches the destination system, but never gets ACKed. I can see the status SYN_SENT on the originating system, and SYN_RCVD on the destination but this is as far as it goes.

      I am completely at a loss here. Does this sound familiar to anyone? Hints and suggestions are greatly appreciated.

      Regards
      Chris

      1 Reply Last reply Reply Quote 0
      • Cry HavokC
        Cry Havok
        last edited by

        So, just checking:

        1. You've got a NAT Rule to forward traffic
        2. You've got a matching firewall rule to allow it
        3. The internal host has the pfSense host as the default gateway
        1 Reply Last reply Reply Quote 0
        • C
          core
          last edited by

          Mea culpa! There was a typo in the default gateway config.  :-[ I would NEVER have thought of rechecking that. You really made my day, cry havok. Thanks!

          1 Reply Last reply Reply Quote 0
          • Cry HavokC
            Cry Havok
            last edited by

            It's an easy mistake to make, from personal experience :)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.