Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to open port 110 or 25 (did with another port)

    Scheduled Pinned Locked Moved Firewalling
    26 Posts 6 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      madmontero
      last edited by

      you said "delete the crap you created" ???

      Let me spool up another fresh VM and try it…  :-\

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        Maybe someone else. IMNSHO, if you cannot tell WAN from LAN and client from server, you should keep your hands miles off any firewall. The default LAN rule allows all traffic go out from LAN (such as Outlook communication with mailserver on WAN). There is absolutely zero need to open anything else, to create any portforwards on LAN or any similar nonsense.

        1 Reply Last reply Reply Quote 0
        • H
          hda
          last edited by

          @madmontero:

          …
          Actually ALL ports are pretty much blocked!
          ...

          You do not need to open up WAN to send & pop email. So yes your ports from outside are blocked.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            And BTW, you should use 587 for sending email and 995 (POP3/S) for downloading email. Not send out your credentials in plaintext. (Also, at least TCP/25 is blocked tons of ISPs.)

            1 Reply Last reply Reply Quote 0
            • M
              madmontero
              last edited by

              @doktornotor:

              Maybe someone else. IMNSHO, if you cannot tell WAN from LAN and client from server, you should keep your hands miles off any firewall. The default LAN rule allows all traffic go out from LAN (such as Outlook communication with mailserver on WAN). There is absolutely zero need to open anything else, to create any portforwards on LAN or any similar nonsense.

              Thanks! this is what I was looking for.. just an easy, simple explanation.

              As for the 587/995… They don't use this...This is from GoDaddy

              Next to Outgoing Server (SMTP), type 465. Click OK and click Next.
              If those settings don't work,repeat steps 1-3 and select None for Use the following type of encrypted connection. Try these other ports for Outgoing server (SMTP): 80, 3535, or 25

              HDA, thanks for the response.. again, these are just a few client machines that need to access pop/smtp email from behind the PFsense.

              I'll let you guys know in a bit!

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                agreed 25 outbound to everything other than the ISP smtp servers is blocked on many isps..  You can thank the spammers and malware/viruses that turn boxes into spam senders for that.

                "Incoming mail server    pop.secureserver.net
                Outgoing mail server (SMTP) smtpout.secureserver.net"

                If you have clients behind pfsense on your lan that need to talk to those servers outside pfsense, ie the internet (wan) then you have nothing to do with port forwards or specific rules if you have the default any any rule on the lan.  This allows lan clients to talk to anything on the internet, ports or protocols.

                If you can not talk to those servers on 25 and or 110 then talk to your ISP..  But as stated you shouldn't be using 25 or 110 to talk to that mail server outside anyway - as dok stated you should use secure methods so your username and password is not sent in the clear across the public net.  The 587 is normally allowed by isps while 25 is not.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • H
                  hda
                  last edited by

                  @madmontero:

                  Thanks! this is what I was looking for.. just an easy, simple explanation.

                  Again, read a few easy knowhow bytes.

                  You need the allow-rules row (2 & 3) in your Firewall: Rules LAN. And delete (1, 4 & 5)
                  Empty Firewall: Rules Floating()

                  IF you do not appreciate initiative from global or not serve to global, then:
                  Empty Firewall: Rules WAN()
                  Empty Firewall: NAT: Port Forward()

                  1 Reply Last reply Reply Quote 0
                  • M
                    madmontero
                    last edited by

                    Thank you guys for the help! I got it working.. did exactly as you (ALL) said and everything is cool  8)

                    I"m used to working on Sonicwall NSA's and Fortigate's but just have this running at one site and it's been fine forever until this upgrade. I thought it was corrupted.

                    Thanks again for all your help! Even DOK  ;)

                    1 Reply Last reply Reply Quote 0
                    • 2
                      2chemlud Banned
                      last edited by

                      Fine! :-)

                      Would you mind sharing your firewall ruleset for a final check here?

                      Just to confirm that all issues are fixed!

                      1 Reply Last reply Reply Quote 0
                      • M
                        madmontero
                        last edited by

                        So here's my final config.. pretty barebone.. one thing I was going to hit up Johnpoz on or post in the VM forum is my Intel NIC card (dual GbE server) seems to just be turning off or shutting down now after some heavy use. e1000 drivers. Never did this on straight 5.5 and prev PF version. I only upgraded to U2 to run 2.2.2

                        And just FYI.. I bought like 5 of these years back.. been working fine on my ESXi and Windows boxes. Just now it's crapping out on PFsense.

                        Thanks!

                        http://www.ebay.com/itm/271581912527?_trksid=p2060353.m1438.l2649&ssPageName=STRK%3AMEBIDX%3AIT

                        P.S. I just Disable hardware checksum offload to see if that helps or does anything.

                        Nat-portFWD.PNG
                        Nat-portFWD.PNG_thumb
                        FW-rulesWAN.PNG
                        FW-rulesWAN.PNG_thumb
                        FW-rulesLAN.PNG
                        FW-rulesLAN.PNG_thumb
                        vswitch.PNG
                        vswitch.PNG_thumb

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          I would of named your port groups wan and lan ;)  But maybe thats just me ;)

                          I don't have any of those specific nics, I have run both vmx3 and e1000 on it my setup currently using the e1000 because of the vmx3 has issue with reporting duplex and ladvd using to send out cdp and lldp from pfsense was having my switch saying there was a duplex mismatch, etc.

                          What is that port forward for?  That is an ODD ball port.. Your not using Xsan are you??

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • M
                            madmontero
                            last edited by

                            I'm running a custom a NVR with Blue Iris.

                            As for the NIC/ESXi issue, I think maybe that card is dying out (what are the odds??) going to swap it out and see. I've been running the e1000 driver on those cheap Chinese units without issue. Also tested in passthrough as well.

                            To find a deal on PCI-e Intel server cards is hard  :(

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              And why would you have that open to the public net??  Doesn't seem like a good idea to me to allow public access to video cameras in my home ;)

                              Why would you not just vpn in if you wan to view the video while remote?

                              42$ seems like a pretty good price to me
                              http://www.amazon.com/Intel-1000-Dual-Server-Adapter/dp/B000BMZHX2

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              1 Reply Last reply Reply Quote 0
                              • M
                                madmontero
                                last edited by

                                It's not a home, and that doesn't allow access to the cameras. It's for admin access only. The camera access are on a internal vlan that only a few have access to. no outside access.

                                Thanks for the link! I ordered a few off Ebay, Both PCI and PCIe  ;)

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  work/home - I wouldn't be allowing access to NVR eitherway

                                  VPN to access anything of that sort..  If you don't want the public to access it "It's for admin access only" then should be through a vpn.

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.