Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
[SOLVED] Source port rewriting: possibility to limit range?
« previous
next »
Print
Pages: [
1
]
Author
Topic: [SOLVED] Source port rewriting: possibility to limit range? (Read 1152 times)
alh
Full Member
Posts: 123
Karma: 6
[SOLVED] Source port rewriting: possibility to limit range?
«
on:
November 03, 2023, 09:18:36 am »
I use OPNsense behind a stateless firewall. I noticed that the source port randomization does not stick to the ephemeral port range (e. g. TCP 32768-65535) but seems to be using anything > 1024 (FreeBSD AFAIK uses 49152-65535 only). So I was wondering if there is a possibility to set the port range that can be used as ephemeral port range in OPNsense or if I need to disable source port rewriting or open up the whole range (>1024) in the stateless firewall. Thanks for your input.
«
Last Edit: November 04, 2023, 09:11:46 pm by alh
»
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1595
Karma: 176
Re: Source port rewriting: possibility to limit range?
«
Reply #1 on:
November 03, 2023, 09:29:24 am »
Do you mean the source port randomization of NAT Overload (aka MASQ, Outbound NAT, SNAT)?
I think you can put something like 50000:60000 as range in "Translation / Port" in a manual "Firewall: NAT: Outbound rule" to limit the NAT pool to this range. But I never did it before, the configuration seems to accept it though.
Logged
Hardware:
DEC740
meyergru
Hero Member
Posts: 1680
Karma: 165
IT Aficionado
Re: Source port rewriting: possibility to limit range?
«
Reply #2 on:
November 03, 2023, 11:02:41 am »
If you want to set it globally, have a look at: "sysctl net.inet.ip.portrange".
However, be aware that the ancient portrange of 49152-65535 has been abolished around FreeBSD 11.1 for a good reason, as with firewalls, you probably need more ephemeral ports for NAT and other purposes.
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005
1100 down / 440 up
,
Bufferbloat A+
alh
Full Member
Posts: 123
Karma: 6
Re: Source port rewriting: possibility to limit range?
«
Reply #3 on:
November 03, 2023, 01:22:05 pm »
Thanks a lot for your reply. I will play with this a little bit and feedback here.
Logged
alh
Full Member
Posts: 123
Karma: 6
Re: Source port rewriting: possibility to limit range?
«
Reply #4 on:
November 04, 2023, 09:11:29 pm »
Both options do the job. Thanks a lot.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
[SOLVED] Source port rewriting: possibility to limit range?