Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Creating firewall rule

    Firewalling
    6
    10
    3583
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cconk01 last edited by

      First - I have searched and looked at the FAQ and documentation section. I have also read quite a few threads, but I can figure out why im not able to open for 53 from the wan to an ip on the lan.

      under wan:
      TCP/UDP  *  53(dns)  10.0.2.254(DNS server on Lan)  53(dns)  *  *

      whenever I perform a grc scan it shows as stealth.

      Im sure im over looking something stupid. Anyways, thanks for any help.

      cconk01

      1 Reply Last reply Reply Quote 0
      • K
        kpa last edited by

        Source port needs to be set to any instead of 53.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschli
          GruensFroeschli last edited by

          As kpa said :)

          If a client opens a connection the source is something random.
          Only the destination is defined.
          The source is normally about between 20000 and 60000 (just something high).

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • C
            cconk01 last edited by

            Here is what I have now and it still doesnt want to work….

            TCP/UDP  *  *  10.0.2.254  53 (DNS)  *    DNS

            Any ideas?

            1 Reply Last reply Reply Quote 0
            • P
              Perry last edited by

              Did you Port Forward it?

              You should really make a diagram.

              /Perry
              doc.pfsense.org

              1 Reply Last reply Reply Quote 0
              • S
                Simoo last edited by

                This is an interesting post as I was just about to post up with a similar question,

                cconk01:
                You need to add the port forward first under 'NAT' then make sure the box at the bottom is ticked that says 'Add firewall rule also' (or something). Then you will be sorted.

                Could any one explain why the source port in the NAT rule is the same as the destination but not in the firewall rule?

                1 Reply Last reply Reply Quote 0
                • dotdash
                  dotdash last edited by

                  @Simoo:

                  Could any one explain why the source port in the NAT rule is the same as the destination but not in the firewall rule?

                  http://en.wikipedia.org/wiki/TCP_and_UDP_port
                  Breifly- The NAT rule only cares about the destination port- the external and the local port. This is so you can listen on a different port on the public/external address than the internal service listens on. For example, you could have two webservers running on port 80 (local port) on a single public ip on ports 80 and 88 (external port) using NAT.
                  The firewall rule normally only cares about the destination port. There is a reason it has the following disclaimer when you set the source port:
                  NOTE: You will not need to enter anything here in 99.99999% of the circumstances. If you're unsure, do not enter anything here!

                  1 Reply Last reply Reply Quote 0
                  • S
                    Simoo last edited by

                    :) Thanks for that, I'll have a good read up…

                    1 Reply Last reply Reply Quote 0
                    • C
                      cconk01 last edited by

                      Sory for takign so long to get back to everyone. No I did not port forward the rule. I believe this is my error. I will give it a shot when I get home.

                      Thanks
                      CCONK01

                      1 Reply Last reply Reply Quote 0
                      • C
                        cconk01 last edited by

                        That was it! Thanks for the newby help… This has been my first setup of a pfsense and its gone rather well. Again I cant thank you enough. Thanks

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post