Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» NAT» Port forwarding only working to /24 addresses
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: Port forwarding only working to /24 addresses  (Read 720 times)
0 Members and 1 Guest are viewing this topic.
NoMiT
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: February 23, 2012, 06:22:59 pm »

Hello all, Thanks for in advance for reading my question.

My Pfsense setup is on a /16 subnet(The lan interface is 192.168.1.1/16) with devices ranging from 192.168.0-255.0-255 and they all can use the gateway fine and access the WAN correctly.

However I simply do not understand what Port forwarding is doing.

If I forward port 7000 from a WAN address to a device on the lan(192.168.1.232/16 for example) it will not work, UNLESS I change the subnet on the 192.168.1.232 device to /24.

Example addresses of Port forwarding working
192.168.1.232 With a Subnet of 255.255.255.0
192.168.13.180 With a Subnet of 255.255.255.0

Example addresses of Port forwarding not working
192.168.1.232 With a Subnet of 255.255.0.0
192.168.13.180 With a Subnet of 255.255.0.0


I have tried different ports/devices and everytime it only works if the lan device is set to a /24 subnet.

Any ideas?
Logged
marcelloc
Hero Member
*****
Offline Offline

Posts: 8157



View Profile
« Reply #1 on: February 23, 2012, 06:55:11 pm »

I have nat configured on /22 networks with no issues, can you post a screenshot of your nat rule?
Logged

Have I helped you? Donations are always welcome! Grin

Te ajudei? Doações são sempre bem vindas! Grin
cmb
Administrator
Hero Member
*****
Offline Offline

Posts: 6055


View Profile WWW
« Reply #2 on: February 23, 2012, 08:24:17 pm »

what's the source IP of the host you're port forwarding traffic from? Out on the Internet, or on a private network? my first guess is you're forwarding in from a 192.168.x.x network and hosts with a /16 mask see that as a local network, which means the replies won't go anywhere.
Logged

pfSense Commercial Support

Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
NoMiT
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #3 on: February 24, 2012, 08:27:27 am »

Thank you guys for the replies. I posted 3 images. One of my LAN interface, one of the port forward, and one of the related rule.

I am forwarding the port from WAN address which is a public facing IP on a /5 subnet (It is not a 192 address)
Logged
marcelloc
Hero Member
*****
Offline Offline

Posts: 8157



View Profile
« Reply #4 on: February 24, 2012, 08:46:12 am »

I did not found erros on your config.
Do your wan has a valid ip?
Logged

Have I helped you? Donations are always welcome! Grin

Te ajudei? Doações são sempre bem vindas! Grin
NoMiT
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #5 on: February 24, 2012, 09:06:49 am »

Yes it has a valid wan ip, and I can access the internet via internal devices on both /24 and /16 subnets, but the really odd part is that the ports forwards work fine if I change the device to a /24.

Right now the websites in question are available and being used (Because I switched their internal ip to a /24), but it is really annoying to have to segment parts of our internal network for no logical reason.
Logged
cmb
Administrator
Hero Member
*****
Offline Offline

Posts: 6055


View Profile WWW
« Reply #6 on: February 24, 2012, 09:23:08 am »

Time to packet capture, start with the LAN on the firewall, filter on the destination host's IP. If you see it leaving there, go to the target server and capture.
Logged

pfSense Commercial Support

Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.027 seconds with 19 queries.