NAT stops working

Started by ramikilany, July 29, 2024, 09:24:53 AM

Previous topic - Next topic
After the upgrade to the latest version (24.7) I can not access any of my web GUI through the WAN interface which with the same IP before the upgrade was working very will.

Did you check the firewall logs if something got blocked and why?


In firewall rules generally I don't see any problems, also what I did I created a full access rule in the firewall on WAN and allow every thing, same issue can not access from external links our servers.

Hi,
I've also updated from 24.1 to the latest OPNSense version 24.7_x and I suffer the same issue. (almost)
I have an internal NGINX Proxy Manager that respond to TCP 443 via a NAT rule from internet, and all the websites he manages (internal hosts) are unreachable after the upgrade.
Obviously OPNSense web GUI is listenng on HTTP on port 85 and HTTPS is not used for web GUI.
I really don't understand what is goin on here...
Any help would be really appreciated.
Cheers.


I was hoping you would tell us about your efforts to narrow this down?


Cheers,
Franco

Same here after update 24.7.2 all of my children can't use there console anymore..

Trying to recreate rule etc nothing ...
I installed UPNP, there are ports in it but it doesn't seem to work

No error or log for help :s

Quote from: zyon on August 23, 2024, 03:27:56 PM
Same here

Uhm, no... this issue was about accessing firewall webgui via WAN IP.
Then, someone came pulling in some undescribed nginx reverse proxying.
Then you came to pull in UPnP and gaming consoles.

Start your own topic with some useful data beyond "it broke after upgrade".

Thanks Dok ......................

September 30, 2024, 12:08:59 PM #10 Last Edit: September 30, 2024, 12:17:38 PM by JakubJB
There's definitely an issue after upgrade. I lost all NAT rules. After comparing config files before and after I see that new empty section showd up:

      <Filter version="1.0.3">
        <rules/>
        <snatrules/>
        <npt/>
      </Filter>

In "before" config all rules are int <nat> section and they're present also in "after"one, but are obviously ignored.
After adding 1:1 rule it show under new section mentioned above, but in not visible before, but named the same as in older config: <onetoone>