• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Port forwarding not working (2.2.3)

NAT
7
23
4.6k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    pfguy
    last edited by Jul 24, 2015, 10:06 AM

    @Supermule:

    Whats your public IP and do you block private networks on WAN??

    no i dont block private networks

    ![private networks.png](/public/imported_attachments/1/private networks.png)
    ![private networks.png_thumb](/public/imported_attachments/1/private networks.png_thumb)

    1 Reply Last reply Reply Quote 0
    • P
      pfguy
      last edited by Jul 24, 2015, 10:10 AM

      @doktornotor:

      As noted above - Diagnostics - Packet Capture.

      here is the Packet Cap:

      17:08:10.564104 IP 118.69.32.168.56244 > 1.54.108.71.80: tcp 0
      17:08:11.561775 IP 118.69.32.168.56244 > 1.54.108.71.80: tcp 0
      17:08:13.566616 IP 118.69.32.168.56244 > 1.54.108.71.80: tcp 0

      1 Reply Last reply Reply Quote 0
      • P
        pfguy
        last edited by Jul 27, 2015, 4:13 PM

        does anyone have any idea why this ís not working ??  :-\

        1 Reply Last reply Reply Quote 0
        • C
          chpalmer
          last edited by Jul 27, 2015, 4:40 PM

          Looks like your pfSense box is passing the traffic just fine.

          What do you have between your box and the camera DVR?

          Triggering snowflakes one by one..
          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

          1 Reply Last reply Reply Quote 0
          • D
            Derelict LAYER 8 Netgate
            last edited by Jul 27, 2015, 10:04 PM

            So you know the traffic is making it to WAN.  Now turn on logging on the WAN firewall rule (The one NAT auto-created) and see what that shows in the firewall log.

            And one more time for good measure:

            https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • P
              pfguy
              last edited by Jul 28, 2015, 5:14 AM Jul 28, 2015, 3:56 AM

              nothing between the Sense box and PVR
              I can access the DVR from LAN no problems !

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by Jul 28, 2015, 2:12 PM

                "I can access the DVR from LAN no problems !"

                And does your DVR know how to get off the LAN, does it have a gateway set..  Network devices can talk on their own network without any need for a gateway.  But when your coming from an internet IP with a port forward, they have to know how to get off their network - ie a gateway (pfsense lan IP)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • P
                  pfguy
                  last edited by Jul 28, 2015, 4:22 PM

                  @johnpoz:

                  "I can access the DVR from LAN no problems !"

                  And does your DVR know how to get off the LAN, does it have a gateway set..  Network devices can talk on their own network without any need for a gateway.  But when your coming from an internet IP with a port forward, they have to know how to get off their network - ie a gateway (pfsense lan IP)

                  yes, i have assigned the DVR a static IP address togather with a gateway address (which is the Sense LAN IP)

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Jul 28, 2015, 8:41 PM Jul 28, 2015, 8:38 PM

                    well if pfsense is sending on the traffic? as you see in a lan sniff are you seeing the answer?

                    These issues are really 10 seconds to troubleshoot – basic 101 networking..  Is the traffic seen on wan?  Does it get sent out the lan to the correct IP..  Do you see a response?

                    I can assure there is no issues with port forwarding in 2.2.3 nor 2.2.4 -- nor do I recall any issues with port forwarding going back to the first version of pfsense I used like 1.2.3

                    issues with port forwarding are not setup correctly, traffic never gets to pfsense to forward.  Device doesn't answer or has firewall.

                    the required steps to troubleshoot are clearly laidout in the troubleshooting port forwards doc linked too.

                    You saw traffic on your wan, but I don't see sniff on pfsense lan showing that traffic sent or not.  Please post your port forward rules and your wan firewall rules.

                    And tell us what IP your trying to send too, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Jul 29, 2015, 9:48 PM

                      dude that is great that you sent me login and password in pm.. But what IP?

                      1.54.108.71

                      That is not listening on 80 or 443..

                      but is on 81 – which hits your dvr

                      I did a scan - and you have something in front of pfsense doing something - because that is not a pfsense box looks on a scan with nmap.. Your showing filtered on 135 for example..  Why would 53 tcp be open.

                      I would love to login and take a look - but you did not give me the details to do so.

                      dvronport81.png
                      dvronport81.png_thumb

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator
                        last edited by Aug 1, 2015, 10:04 AM Aug 1, 2015, 9:59 AM

                        Ok your fixed up - dude you had captive portal on..  Going to look if that is listed in the port forwarding troubleshooting.. How is the server suppose to talk back?  So I put the mac of that 192.168.1.5 box you were forwarding to in the mac pass section, where you had your dad listed.

                        Now I hit your IP on 80 and get login page

                        Also I sent you in your PM – don't use any any on wan!!  Bad Bad idea, if you want to allow access to gui.. Limit it to the port the gui is on and your wan address.  And best you should of just asked me for my IP or looked in your logs for when I tried to use your vpn.

                        Do you want me to fix that - since its broken.. And PPTP is horrific out of date and not secure, you should just use openvpn..

                        edit
                        Just looked on the port forwarding troubleshooting guide that you went through??  Clearly not, item 9 in common problems
                        9. Forwarding ports to a server behind a Captive Portal. An IP bypass must be added both to and from the server's IP in order for a port forward to work behind a Captive Portal.

                        workingdvr.png
                        workingdvr.png_thumb

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • P
                          pfguy
                          last edited by Aug 2, 2015, 5:14 PM

                          i was about to post a conclusion to this thread to thank @johnpoz for his valuable help !!
                          Anyway, all the experience in this thread was already stated in the post above by the original problem solver @johnpoz.
                          thank you so much @johnpoz and everyone else who have replied in this thread.

                          1 Reply Last reply Reply Quote 0
                          21 out of 23
                          • First post
                            21/23
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.