os-upnp plugin not working?

Started by Warbreaker, July 16, 2026, 03:12:47 PM

Previous topic - Next topic
July 16, 2026, 03:12:47 PM Last Edit: July 16, 2026, 03:16:09 PM by Warbreaker
I moved to 26.7, my old firewall rules in 26.1 was already moved to the new rules set format so I imagine that's good on 26.7
But when I look at UPnP mappings I see this:
IP address Port External port Protocol Remote IP Remote port Added via / description
? 22419 22419 UDP any any UPnP IGD / DemonwarePortMapping

No IP address and it seems to not be working (My son is my tester with Destiny 2 complaining about strict NAT), it was working on 26.1

Quote from: Warbreaker on July 16, 2026, 03:12:47 PM(My son is my tester with Destiny 2 complaining about strict NAT)
Configure the following for him :
- Static DHCP IP Address Mapping based on the MAC Address of his PC/Console.
- Enter that IP Address in a new Alias called GAMING_Clients or something like that.
- Switch to Hybrid NAT Mode
- Create a Manual NAT Rule with Strict-port Enabled and as Source the Alias GAMING_Clients.

He will now always at least have Moderated NAT and could even continue gaming without uPnP Enabled :)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

I will probably do that at some point, but thought on reporting it as well, either something is broken or the stronger rules on 26.7 is making the old plugin not work at all, for security reasons of course I have only one ACL on my UPnP plugin to just allow non privileged ports to be bound.

It would be interesting to know why it isn't working anymore.

So i've been battling this today, oddly Destiny 2 was my guinea pig too lol

So as far is i can tell miniupnpd seems to struggle to bind the client IP to the port request, now if i roll back to my deployment of 26.1.x this is a non issue. The unfortunate thing also though is i found the stuggestion nero gave to not work either which is odd.

I have yet to go down the port forward route yet mostly because if that works i'll shelf opnsense in favour of another router as i don't have the time or the will to map all the ports of every game that gets played in this house lol.

I have different network segments for different tasks (IoT, Servers, Gaming, Work etc) because i'm lazy uPnP is excellent for the gaming segment (a cheeky /29 subnet) as there are no access rules to other VLANs from there so it can go mental for all I care (before some karen shouts about security and how uPnP is a infiltration waiting to happen).

But judging on how the intel microcode plugin is causing issues i'm just going to assume it's a bug in the network stack somewhere and wait to see what happens maybe the kids will go outside for once.........

Quote from: Baron_Backdoor on July 18, 2026, 08:58:12 PMThe unfortunate thing also though is i found the stuggestion nero gave to not work either which is odd.
Hmm... that sucks... :'(

Did you check https://docs.opnsense.org/ to make sure you have not missed anything ?
My post was more a quick guide line than an actual HowTo :)

QuoteI have yet to go down the port forward route yet mostly because if that works i'll shelf opnsense in favour of another router as i don't have the time or the will to map all the ports of every game that gets played in this house lol.
That sucks indeed and is something I would never do either!

QuoteI have different network segments for different tasks (IoT, Servers, Gaming, Work etc) because i'm lazy uPnP is excellent for the gaming segment (a cheeky /29 subnet) as there are no access rules to other VLANs from there so it can go mental for all I care (before some karen shouts about security and how uPnP is a infiltration waiting to happen).
This "Karen" APPROVES!!! ;)

QuoteBut judging on how the intel microcode plugin is causing issues i'm just going to assume it's a bug in the network stack somewhere and wait to see what happens maybe the kids will go outside for once.........
LOL! NICE! ^_^
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

Confirming issues immediately after an upgrade to 26.7 as well

It seems to be partially working though, as some entries/mappings are being made. And now the "IP address" column is just showing "?" for all entries, instead of the local IP as in previous versions. Not sure if that could help point the finger at the actual issue

Quote from: poeBaer on July 18, 2026, 11:38:46 PMConfirming issues immediately after an upgrade to 26.7 as well

It seems to be partially working though, as some entries/mappings are being made. And now the "IP address" column is just showing "?" for all entries, instead of the local IP as in previous versions. Not sure if that could help point the finger at the actual issue

This is exactly what's happening to me, the IP address column is just ? and while it attempts to add entries to the firewall, uPnP is failing to do so.

I already had migrated my old firewall rules in 26.1 to the new rules set and all of my other rules are working as expected, the firewall seems fine, including my port 53 and 123 interception for the firewall own services.

So for now I just disabled the service until it is confirmed is fixed, but glad it wasn't just a me issue ;-)

Quote from: Warbreaker on July 19, 2026, 12:41:58 PM
Quote from: poeBaer on July 18, 2026, 11:38:46 PMConfirming issues immediately after an upgrade to 26.7 as well

It seems to be partially working though, as some entries/mappings are being made. And now the "IP address" column is just showing "?" for all entries, instead of the local IP as in previous versions. Not sure if that could help point the finger at the actual issue

This is exactly what's happening to me, the IP address column is just ? and while it attempts to add entries to the firewall, uPnP is failing to do so.

I already had migrated my old firewall rules in 26.1 to the new rules set and all of my other rules are working as expected, the firewall seems fine, including my port 53 and 123 interception for the firewall own services.

So for now I just disabled the service until it is confirmed is fixed, but glad it wasn't just a me issue ;-)
I'm seeing the ? under IP as well, but my firewall DOES seem to be creating the maps. My plex server and my girlfriend's PC have both managed to create maps and I've verified the ports are indeed open. Do you have Source NAT configured for static port? I migrated that from the old Outbound NAT section on 26.1 before upgrading and things seem to be operating correctly, despite the visual glitch in the UPNP service page.

Today at 10:26:50 AM #8 Last Edit: Today at 10:28:46 AM by Warbreaker
Quote from: Chris123NT on Today at 01:31:11 AMI migrated that from the old Outbound NAT section on 26.1 before upgrading and things seem to be operating correctly, despite the visual glitch in the UPNP service page.

In the past when I installed OPNSense back in 26.1 I migrated to the new firewall rules.

I had my source NAT configured as Hybrid in 26.1 and it was working for 26.1, in 26.7 it is in Hybrid mode too, besides the visual glitch, was there something I needed to do?

My understanding is that I had already made the modifications required, but maybe I missed something?

My test subject is my son's Destiny 2 and that stopped working for 26.7, I mean you can NAT but you cannot map ports properly, they show as mapped but no IP address and Destiny complains about it so it is not working as it was in 26.1

Quote from: Warbreaker on Today at 10:26:50 AM
Quote from: Chris123NT on Today at 01:31:11 AMI migrated that from the old Outbound NAT section on 26.1 before upgrading and things seem to be operating correctly, despite the visual glitch in the UPNP service page.

In the past when I installed OPNSense back in 26.1 I migrated to the new firewall rules.

I had my source NAT configured as Hybrid in 26.1 and it was working for 26.1, in 26.7 it is in Hybrid mode too, besides the visual glitch, was there something I needed to do?

My understanding is that I had already made the modifications required, but maybe I missed something?

My test subject is my son's Destiny 2 and that stopped working for 26.7, I mean you can NAT but you cannot map ports properly, they show as mapped but no IP address and Destiny complains about it so it is not working as it was in 26.1
No, you did everything correctly, source NAT with hybrid rules, and you set Static port right? That last bit is important to get things to stop complaining. Like I said, I am also seeing the ? instead of an IP under maps but I verified multiple times with multiple different games/software that the ports ARE opening and being routed to the correct PCs. If I remember from back when I played Destiny 2 like 10 years ago, I had to go through a whole song and dance to make that game work with PFSense, I have ACL rules set up in the UPNP plugin because I seem to remember that being the trick with PFSense but I'm not sure if that's doing anything here.

As far as I can tell it's working other than the visual bug, at least it's passing the girlfriend test so I don't have to explain why the internet is messed up lol.

Quote from: Chris123NT on Today at 04:20:12 PMand you set Static port right?

What is this last bit exactly? Maybe is something silly I haven't done or did before but need to redo for 26.7

facing the same thing. Migrated from 26.1.10 and I get the "?" as well, BUT, it seems PS5 /qbttorent/others are still being mapped and working correctly.

Quote from: Warbreaker on Today at 05:39:41 PM
Quote from: Chris123NT on Today at 04:20:12 PMand you set Static port right?

What is this last bit exactly? Maybe is something silly I haven't done or did before but need to redo for 26.7
I believe I had to tick on the advanced options in the source nat rule while creating it, but it's a check box called static port.

Today at 08:00:36 PM #13 Last Edit: Today at 08:05:59 PM by Warbreaker
I finally got it working.

I added this "Source NAT" rule:
https://www.pasteboard.co/lTHlqpZ_SWPY.png

And I guess combined with this UPnP rule it should only bind non privileged ports, it should be good:
https://www.pasteboard.co/rmGUkErct6gE.png

Note: I can't make images work on this forum for some reason.