• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

NAT with SOAP

Scheduled Pinned Locked Moved NAT
5 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    enigmait
    last edited by May 2, 2015, 12:12 PM

    Hi,

    I run a cpanel server inside pfsense using nat.

    Everything works fine except for soap requests.

    When I perform a test I get a timeout and I can only guess that it is something to do with the request not coming back through the correct route.

    It's only a theory that this is the problem but now I am stuck on what to do.

    Has anyone had a similar issue and is able to help to resolve it?

    1 Reply Last reply Reply Quote 0
    • D
      dennypage
      last edited by May 2, 2015, 2:14 PM

      Have you looked in the firewall log to see if any packets are being blocked?

      Status -> System Logs -> Firewall

      1 Reply Last reply Reply Quote 0
      • E
        enigmait
        last edited by May 3, 2015, 2:04 PM

        Yes. Nothing in the logs. Anywhere.

        1 Reply Last reply Reply Quote 0
        • D
          dennypage
          last edited by May 3, 2015, 3:16 PM

          If there's nothing in pf's firewall log then it's likely that pf isn't directly involved in the failure. My next step would be a packet capture. Other things to check would be host firewall and host routing.

          1 Reply Last reply Reply Quote 0
          • S
            salamihawk
            last edited by May 4, 2015, 9:38 AM

            You have to think through logically how the SOAP protocol works and where your source and destination IPs are. Are you sending something from the internet into your local network? Is port 80 (this is what SOAP uses, no?) properly forwarded? Is port 80 maybe being intercepted by the management process of the pfSense firewall? Does SOAP require any funky backwards (server to client) or secondary connections (connect to 80, negotiate client-server connect to other port a la RPC) that might not be forwarded properly?

            One other thing you can try is to define a custom service with the destination port TCP 80 and set the inbound (internet -> server) policy to use this new TCP 80 service and not the built-in HTTP service. Some firewalls (I'm not too familiar with pfSense, admittedly) have helper-processes that look deep into the application layer to see what's going on in the application stream, and if the SOAP protocol "looks" different than a regular HTTP request, the firewall may flag it as invalid and drop the packets. Defining a custom service will tell the firewall to only look at layer 4 (TCP/UDP Ports) and no further, ensuring that non-standard protocols using standard ports will be properly forwarded without firewall interference.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received