Jump to content
Not connected, Your IP: 18.226.251.22

Recommended Posts

Hi, I've seen several threads on this subject but none with any definitive answers or solutions.
I'm on pfSense 2.4.5, and I've setup a remote port forward for 40756
1604138651_Screenshot2021-02-10at19_36_41.png.79df65e56d8743806c5f23e497f41051.png 

I've setup an NAT port forwarding rule on pfSense as described here. Here's the rule...
1503355413_pfSense.local.lan-FirewallNATPortForwardEdit.thumb.jpg.9356910c5ab91dbd4316a57cd13f32d7.jpg

The TCP test on AirVPN stays grey and never turns green. I've tried deleting the remote post and creating a new on several times, I've never managed to get this to work. I have set the same port in my Torrent client, which is always reported as being closed. I wouldn't say I'm hugely technically savvy but I can usually mange to figure things out by googling for hours and reading A LOT but I'm drawing a blank here. Why doesn't this work?

Here's a packet capture I did from pfSense while running the TCP test, I set it level of detail to "Full":

20:00:06.108044 AF IPv4 (2), length 80: (tos 0x0, ttl 54, id 10076, offset 0, flags [DF], proto UDP (17), length 76)
    188.166.175.60.59010 > XX.XX.XXX.XX.40756: [udp sum ok] UDP, length 48
20:00:11.284073 AF IPv4 (2), length 64: (tos 0x0, ttl 54, id 5974, offset 0, flags [DF], proto TCP (6), length 60)
    188.166.175.60.53688 > XX.XX.XXX.XX.40756: Flags , cksum 0xb10f (correct), seq 1850573718, win 29200, options [mss 1285,nop,nop,TS val 1356960960 ecr 0,nop,wscale 6], length 0
20:00:12.308635 AF IPv4 (2), length 64: (tos 0x0, ttl 54, id 5975, offset 0, flags [DF], proto TCP (6), length 60)
    188.166.175.60.53688 > XX.XX.XXX.XX.40756: Flags , cksum 0xb00f (correct), seq 1850573718, win 29200, options [mss 1285,nop,nop,TS val 1356961216 ecr 0,nop,wscale 6], length 0
20:00:14.323413 AF IPv4 (2), length 64: (tos 0x0, ttl 54, id 5976, offset 0, flags [DF], proto TCP (6), length 60)
    188.166.175.60.53688 > XX.XX.XXX.XX.40756: Flags , cksum 0xae17 (correct), seq 1850573718, win 29200, options [mss 1285,nop,nop,TS val 1356961720 ecr 0,nop,wscale 6], length 0


Anyone have any ideas?

Share this post


Link to post

My two immediate guesses would be 
I) your behind a CGNAT type WAN connection. 
ii) the port forward is working but the service running behind your firewall isn’t listening on that port, or is blocked. 

Can you show us your inbound interface firewall rules too. 

Share this post


Link to post

I'm going to post the rest of my VPN related firewall rules later (busy with work stuff right now) - hopefully that will give a complete picture.

Share this post


Link to post
Posted ... (edited)

Ok here's the rest of my Firewall Rules (relating to AirVPN)...

So my torrent client is part of of the vpn_redirect_group alias (on LAN) and also has it's own alias of torrent_client the port forward from AirVPN: 40756 has an alias of torrent_inbound_port.

Here are my NAT port forwards:
410769347_FirewallNATPortforward.thumb.png.b13de65968b40b2959d885538aa371cb.png

Here are my outbound rules...
1243610245_FirewallNATOutbound.thumb.png.62acfaa2fb3f99ccde86acb7acfc3f07.png

338186195_FirewallRulesVPN_WAN.thumb.png.8d0dd93d4d0f33a5e34453e3422a0ca6.png

My LAN rules (not all of them, but showing ones related to AirVPN)
638601584_FirewallRulesLAN.thumb.png.867e40311f850ab1af3ed65b27496c68.png

Rules on VPN_WAN...
338186195_FirewallRulesVPN_WAN.thumb.png.8d0dd93d4d0f33a5e34453e3422a0ca6.png

Finally floating rule to prevent WAN egress...
2096307638_FirewallRulesFloating.thumb.png.180a316a9890aa27839c047d12f1afab.png

That's everything I've got, if anyone can unpick why the remote port forward isn't working that would be great.

Thanks.

Edited ... by circa1665

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...