That and I am running off of 3 hours of sleep because my newborn daughter is giving me 1 to 3 hours of sleep a night
Quote from: MattRidge on September 28, 2023, 07:20:26 pmThat and I am running off of 3 hours of sleep because my newborn daughter is giving me 1 to 3 hours of sleep a nightCongrats! Take good care of her. Eventually the sleep pattern will improve. But you will never ever get that sleep deficit of roughly 1-2 years back Cheers,Franco
Ah the joys of newly born. Glad mine is grown now.Anyways. Disclaimer: I don't do gamins so this is out of my experience. That said isn't the strong NAT a thing about the console/pc needing some way to connect and be connectable with some ports on the game platform?I seem to recall a number of threads with works/doesn't work for port forwards and nats as workarounds to upnp.
Unfortunately, I'm with CM. I don't use xbox and I'm usually the only one gaming. That said, I assume the warning you're getting is Strict NAT and not Strong NAT?Have you made any changes to the defaults? I assume by static ips you mean static dhcp leases.It looks like one of MS solutions is to do port forwarding for both systems and configure one to use custom ports. I dislike this as you then have open ports connected directly to machines on your lan. This is also why I dislike upnp. I have a friend that got hacked because they didn't realize their nas had open ports to the internet.Are you able to see something besides Strict NAT if you just have the pc or xbox on after rebooting OPNSense?
Strong NAT has to do with blocked ports, they can be accessed because the user allowed an app to run, but it's not visible by the outside so your latency/interaction with said program is slower than it should be. It is like opening port 80 on a firewall. I want to know if it's possible to allow access to a port without actually puncturing a hole in the firewall. If not, how do I do it safely? And yeah, having a young kid wasn't in the cards, I will be changing diapers well past my 50th birthday now
Quote from: CJ on September 29, 2023, 02:09:50 pmUnfortunately, I'm with CM. I don't use xbox and I'm usually the only one gaming. That said, I assume the warning you're getting is Strict NAT and not Strong NAT?Have you made any changes to the defaults? I assume by static ips you mean static dhcp leases.It looks like one of MS solutions is to do port forwarding for both systems and configure one to use custom ports. I dislike this as you then have open ports connected directly to machines on your lan. This is also why I dislike upnp. I have a friend that got hacked because they didn't realize their nas had open ports to the internet.Are you able to see something besides Strict NAT if you just have the pc or xbox on after rebooting OPNSense?I've made no changes as of yet, I am still working with a virgin system as it stands now, I am afraid to make a mistake and have my firewall scream to the world "I'm used by an idiot, abuse me!"
Quote from: MattRidge on September 29, 2023, 02:25:09 pmStrong NAT has to do with blocked ports, they can be accessed because the user allowed an app to run, but it's not visible by the outside so your latency/interaction with said program is slower than it should be. It is like opening port 80 on a firewall. I want to know if it's possible to allow access to a port without actually puncturing a hole in the firewall. If not, how do I do it safely? And yeah, having a young kid wasn't in the cards, I will be changing diapers well past my 50th birthday now The MS Xbox NAT page doesn't have an entry for Strong NAT. Are you sure it says Strong NAT or do you mean Strict NAT?https://support.xbox.com/en-US/help/hardware-network/connect-network/xbox-one-nat-errorQuote from: MattRidge on September 29, 2023, 02:27:11 pmQuote from: CJ on September 29, 2023, 02:09:50 pmUnfortunately, I'm with CM. I don't use xbox and I'm usually the only one gaming. That said, I assume the warning you're getting is Strict NAT and not Strong NAT?Have you made any changes to the defaults? I assume by static ips you mean static dhcp leases.It looks like one of MS solutions is to do port forwarding for both systems and configure one to use custom ports. I dislike this as you then have open ports connected directly to machines on your lan. This is also why I dislike upnp. I have a friend that got hacked because they didn't realize their nas had open ports to the internet.Are you able to see something besides Strict NAT if you just have the pc or xbox on after rebooting OPNSense?I've made no changes as of yet, I am still working with a virgin system as it stands now, I am afraid to make a mistake and have my firewall scream to the world "I'm used by an idiot, abuse me!"The troubleshooting process is definitely helped by you not randomly making changes in order to "fix" things. That said, you didn't answer any of the other questions I asked. Since I don't think any of us have an xbox or multiple, we're having to debug by proxy and that requires a lot more information.And no, if you open a port, the port is open to all. That's why it's not generally recommended and instead you let the firewall only pass through replies to your requests. upnp works by automatically opening ports without telling the user and that's why it's often recommended as a "fix" and why security conscious people recommend turning it off.