Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to allow returning traffic?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DaReaLDeviLD Offline
      DaReaLDeviL
      last edited by

      Hi Friends,

      I have a problem in finding the right rule for going out with traffic over the dyndns and returning into my network again. It is always blocked.

      System>Advanced, Firewall/NAT, check " Bypass firewall rules for traffic on the same interface " don't solve my problem

      I want to leave from 192.168.1.x or 192.168.2.x and go back over dyndns or my ip into one of the two networks.

      What settings are needed to do that?

      Thanks for your help!
      network.png
      network.png_thumb

      VM PFSense 2.4.3 (amd64) on Dell PowerEdge T410
      Xeon E5620 @ 2.40GHz 2 CPUs: 4GB Ram: 60GB Disk
      ISP (MNet) 1xModem (Vigor 130) 1xWan, 3xLan (PFSense)

      1 Reply Last reply Reply Quote 0
      • G Offline
        gordc
        last edited by

        I just worked on this exact problem.  First under system/advanced put a check in "Disable DNS Rebinding Checks"
        Then under system/firewall/nat put a check in Enable NAT Reflection for 1:1 NAT

        Thanks Gord

        1 Reply Last reply Reply Quote 0
        • DaReaLDeviLD Offline
          DaReaLDeviL
          last edited by

          Hi Gordc,

          thanks for your help

          DNS Rebind Check

          Enable NAT Reflection for 1:1 NAT

          but no success :(. Is there anything else to mark or forward?

          VM PFSense 2.4.3 (amd64) on Dell PowerEdge T410
          Xeon E5620 @ 2.40GHz 2 CPUs: 4GB Ram: 60GB Disk
          ISP (MNet) 1xModem (Vigor 130) 1xWan, 3xLan (PFSense)

          1 Reply Last reply Reply Quote 0
          • N Offline
            nothing
            last edited by

            In short words you want to access your real IP from inside.
            Possible only if Zyxel supports NAT reflection.

            1 Reply Last reply Reply Quote 0
            • DaReaLDeviLD Offline
              DaReaLDeviL
              last edited by

              Hmm the zyxel only works as a modem. So it should not affect that I think?! I will have a look at it tomorrow.

              VM PFSense 2.4.3 (amd64) on Dell PowerEdge T410
              Xeon E5620 @ 2.40GHz 2 CPUs: 4GB Ram: 60GB Disk
              ISP (MNet) 1xModem (Vigor 130) 1xWan, 3xLan (PFSense)

              1 Reply Last reply Reply Quote 0
              • DaReaLDeviLD Offline
                DaReaLDeviL
                last edited by

                1. so I now found the right way…

                System -> Advanced -> Firewall and NAT

                Then go down to: NAT Reflection mode for port forwards

                And turn it on with: "Enable (Nat + Proxy)"

                Hope this helps anyone!

                Edit:

                DNS Rebind Check or [ ] Enable NAT Reflection for 1:1 NAT needed!!

                VM PFSense 2.4.3 (amd64) on Dell PowerEdge T410
                Xeon E5620 @ 2.40GHz 2 CPUs: 4GB Ram: 60GB Disk
                ISP (MNet) 1xModem (Vigor 130) 1xWan, 3xLan (PFSense)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.