Can't access my own opened ports from inside of LAN


  • Hello!

    My PF is latest version: 2.1-RELEASE (amd64)  built on Wed Sep 11 18:17:48 EDT 2013
    FreeBSD 8.3-RELEASE-p11
    I have  4 WAN interfaces, every of them has its own subnet.
    I have some ip addresses on my WAN1 interface.
    I create port forwarding, which forwards traffic from WAN1ip1:443 to server in my LAN (192.168.0.198:443) which works fine when I connect from any internet host. But I can't connect to it while trying to do this from other host in my LAN.
    For examle I write on my computer:  telnet WAN1ip1:443 and get the timeout. PF is default gateway for my computer.
    My web server in LAN is working, telnet 192.168.0.198:443 get success.
    Looks like the problem is in PF.
    NAT Reflection mode for port forwards is NAT+Proxy, I tried to change it to Pure NAT or even Disabled but it did not help me.
    Help me please to configure PF-Sence to use WANip1:443 to access to my LAN server.


  • I'm having the same problem. I've gotten around it for now by enabling split DNS.

    My thought is to move all the port forwards over to floating and then enable them for the LAN side as well.

    It feels like some NAT reflection setting should have just made this work with the defaults, but isn't.