Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense 2.1 Release - NAT Reflection not working

    Scheduled Pinned Locked Moved NAT
    52 Posts 9 Posters 25.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Daniel.Rollins 0
      last edited by

      The gateways all seem to be OK. Is there a specific thing I should check? I had this problem before the upgrade as well and that was a new install.

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        As you said earlier, it may be a problem with the way you configured your DMZ.  I'm out of swags at this point.
        Thats the old Scientific Wild-Ass Guess
        or in my case the Super Wild-Ass Guess

        Not the new urban dictionary hijacked swag.

        1 Reply Last reply Reply Quote 0
        • S
          Supermule Banned
          last edited by

          Is it possible to have remote access to the thing?

          1 Reply Last reply Reply Quote 0
          • D
            Daniel.Rollins 0
            last edited by

            No, sorry.

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by

              You can use teamviewer to remote in if its installed on a connected computer.

              1 Reply Last reply Reply Quote 0
              • S
                Supermule Banned
                last edited by

                It would be a lot easier to see whats wrong since I have NAT reflection here and its working fine.

                1 Reply Last reply Reply Quote 0
                • D
                  Daniel.Rollins 0
                  last edited by

                  I would be open to using teamviewer or similar to provide access while I watch but I can't just hand out passwords for remote access, especially to people I don't actually know.

                  1 Reply Last reply Reply Quote 0
                  • K
                    kejianshi
                    last edited by

                    You should sit and watch and type all the passwords.  Thats  what is good about teamviewer…  Otherwise I'd just suggest he SSH into your pfsense, proxy back a port and handle it via proxy, which is not smart for you unless you trust alot.

                    1 Reply Last reply Reply Quote 0
                    • S
                      Supermule Banned
                      last edited by

                      Exactly the way I normally handle remote support to external clients.

                      @Daniel.Rollins:

                      I would be open to using teamviewer or similar to provide access while I watch but I can't just hand out passwords for remote access, especially to people I don't actually know.

                      1 Reply Last reply Reply Quote 0
                      • K
                        kejianshi
                        last edited by

                        It would be sort of hard to pull a fast one with someone watching every move unless they didn't know anything about the box at all. :P

                        1 Reply Last reply Reply Quote 0
                        • S
                          Supermule Banned
                          last edited by

                          Depending on the setup…. :)

                          I dont think it would be that timeconsuming. Maybe a couple of hours maximum.

                          1 Reply Last reply Reply Quote 0
                          • D
                            Daniel.Rollins 0
                            last edited by

                            When would you be available to do a Team Viewer session and try to figure this out?

                            1 Reply Last reply Reply Quote 0
                            • S
                              Supermule Banned
                              last edited by

                              What part of the world are you in Daniel?

                              1 Reply Last reply Reply Quote 0
                              • D
                                Daniel.Rollins 0
                                last edited by

                                Utah (Mountain Time) Currently UTC-6.

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Supermule Banned
                                  last edited by

                                  Perfect. Catch you on PM.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    Supermule Banned
                                    last edited by

                                    Problem solved!

                                    1 Reply Last reply Reply Quote 0
                                    • K
                                      kejianshi
                                      last edited by

                                      I'm dying with curiosity - What was the problem?

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        Daniel.Rollins 0
                                        last edited by

                                        On the LAN interface configuration under Static IPV4 Configuration, the gateway should be set as none but I had it set to an internal address on my network. I guess it confused PFSense or something. The fix was to set the gateway back to "none".

                                        Thanks to Supermule for solving that one!

                                        1 Reply Last reply Reply Quote 0
                                        • K
                                          kejianshi
                                          last edited by

                                          Really?  I never would have guessed:

                                          Second page of thread, halfway down:

                                          "I've seen that gateways have been renamed or changed mysteriously upon upgrade by some.
                                          In one case it just killed his RRD data.

                                          In another case the gateway inserted its self into the openvpn and WAN firewall rules.

                                          Could some sort of gateway rename/change/insertion have happened to you?

                                          I'm reaching…"

                                          haha - But yeah.  I think supermule would have known it anyway.

                                          I'm going to put the words "please ignore this" at the bottom of all my posts from now on.    ;D

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            Supermule Banned
                                            last edited by

                                            It was a pleasure working with Daniel and nice to meet a fellow pfsense'r!! :)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.