Bug #6675


Port Forward on LAN does not work in 2.3.x

Added by Tácio Andrade almost 8 years ago. Updated almost 8 years ago.

Not a Bug
Target version:
Start date:
Due date:
% Done:


Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:


Good evening everyone, updated my pfSense from 2.2.6 to 2.3.2 this week and 2 rules Port Forward on the LAN, one to redirect the external DNS queries to my internal server and another to force the other application traffic to a local server stopped working.
I made a laboratory today with all versions of the series 2.3.x only to the rules of port forward and they did not work.
I asked another friend to do the test and the same problem occurred.

Here then a replica of one of the rules in 2.2.6 works perfectly.

Thank you in advance for your help in solving the problem.

Sincerely Tácio Andrade


Actions #1

Updated by Jim Pingle almost 8 years ago

  • Category deleted (NAT Reflection)
  • Status changed from New to Not a Bug
  • Target version deleted (2.3.2-p1)

Reflection wouldn't come into play for a rule such as that. If the client and server are on the same subnet, you need hybrid or manual outbound NAT rules to mask the source. It's possible there is some other backend parsing difference but there are many, many people using rules exactly like that successfully on 2.3.x with proper outbound NAT.

More likely, the config you had was incomplete on 2.2.x but was working by accident due to some other factor in your configuration. Post much more detail on a forum thread and someone can help you diagnose the underlying problem.

Actions #2

Updated by Tácio Andrade almost 8 years ago

If I need is more of the same as Squid is to work with the transparent proxy, redirecting only port 80 and not all traffic.
I tried to enable the transparent proxy on Squid to see which rules it generated, however it did not generate any new rule in NAT> Outbound.

Open a topic in the forum, waiting for someone to help me find a way to recreate this rule, otherwise I will have to run the downgrade.

Actions #3

Updated by Tácio Andrade almost 8 years ago

Only you correcting what you said above in pfSense own documentation just finding something interesting, he recommends that the redicionamento rule DNS is done through Port Forward and not NAT.


Also available in: Atom PDF