Port Forwarding HELP for 26.7.x

Started by Distroyer, October 07, 2026, 01:58:15 AM

Previous topic - Next topic
Hello,

I have been running OPNsense on a dedicated machine for some time, and all my devices and services are behind it. I'm still quite new to networking, so I have mostly configured the default settings and followed a few online guides for specific tasks, but nothing particularly advanced.

Recently, I wanted to play a game with some friends and host a server using my existing infrastructure. The problem is that my OPNsense firewall is behind my ISP's router, which means I have a double NAT setup.

I did not perform any special configuration when I installed OPNsense. I simply connected the OPNsense WAN interface to one of the ISP router's Ethernet ports, and that was it. All my experiments and services run within the OPNsense network, and until now I never needed anything different. However, as soon as I needed external access to something inside my network, I started running into problems.

Specifically, I need help configuring port forwarding. I need to forward port 50505 (UDP) to a specific IP address within my OPNsense network (something like 192.168.1.x).

I understand that I also need to configure port forwarding on the ISP router, and I have no problem doing that. In fact, I tested the same service directly behind the ISP router without OPNsense, and it worked correctly.

However, for some reason, none of the guides I found online, nor the instructions provided by AI tools (Google Search and Microsoft Copilot), have worked in my case. Their explanations seem logical, but no matter what I try, I cannot get it working. That is why I am here looking for a solution specific to my setup.

This is my network infrastructure from the Internet to the service, to provide a complete overview:

Internet → ISP Router → OPNsense WAN* → OPNsense LAN → Server (local IP) running a service on UDP port 50505

* I am currently in the process of implementing High Availability (HA) for my OPNsense setup. Right now, I have two IP addresses assigned by the ISP router, both static: one physical IP and one virtual IP. The HA configuration is not complete yet because I do not have the second device ready. A third IP address has also been reserved for the future setup.

I am not sure whether this unfinished HA configuration could be causing the problem or not, which is one of the reasons I am asking for help.

My current port-forwarding configuration for the double NAT setup is the following:

ISP Router → Forward UDP 50505 to → Virtual IP used by the OPNsense WAN HA configuration → Forward UDP 50505 to → Server with a static IP running the service on UDP 50505

I will attach an screenshot of the relevant configurations that may help explain my setup and show what has already been configured (my layout is in Spanish :P).

If you need any additional information or context, please let me know and I will be happy to provide it.

Thank you.

Quote from: Distroyer on October 07, 2026, 01:58:15 AMMy current port-forwarding configuration for the double NAT setup is the following:

ISP Router → Forward UDP 50505 to → Virtual IP used by the OPNsense WAN HA configuration → Forward UDP 50505 to → Server with a static IP running the service on UDP 50505
If you forward the traffic to the virtual IP on the ISP router, you also have to specify the virtual IP as destination in the NAT rule on OPNsense. It looks like, you left the default WAN address there, however.

Quote from: Distroyer on October 07, 2026, 01:58:15 AM* I am currently in the process of implementing High Availability (HA) for my OPNsense setup.
Remember that your ISP router will still be the single point of failure. So a HA setup only has a limited benefit.

The earth is our single point of failure, when earth 2 please?

(This is only intended as a joke xD)
Hardware:
DEC740

Quote from: Monviech (Cedrik) on October 07, 2026, 06:45:54 PMThe earth is our single point of failure, when earth 2 please?

(This is only intended as a joke xD)
There are shows where they travel between different versions of Earth ^_^


But seriously :

Can anyone tell me why I see people Port Forwarding to WAN and then Redirect to a specific IP Address ?!

I would expect to simply Port Forward directly to the LAN-side IP Address and not WAN ?
The other one I have seen was in this topic : https://forum.opnsense.org/index.php?topic=53086.0

Disclaimer : I have left my "Host Servers at home" time behind me so I have no reason/option to test this and I am really curious :)
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

October 07, 2026, 11:03:44 PM #4 Last Edit: October 07, 2026, 11:11:34 PM by klinebau
Quote from: nero355 on October 07, 2026, 09:12:23 PMThe other one I have seen was in this topic : https://forum.opnsense.org/index.php?topic=53086.0

I think maybe you misunderstood the firewall rule in this topic.  It says for traffic arriving at the WAN address, redirect (or forward for ipv6) to the local network address.