OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • [RESOLVED] Port Forward not working - reply with wrong source port?
« previous next »
  • Print
Pages: [1]

Author Topic: [RESOLVED] Port Forward not working - reply with wrong source port?  (Read 1769 times)

namezero111111

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 10
    • View Profile
[RESOLVED] Port Forward not working - reply with wrong source port?
« on: June 12, 2018, 06:07:20 pm »
Dear folks,

I am not seeing this error right away. Trying to NAT and port forward with the following rule as attached.
WAN is 192.168.254.2/24 (NAT If)
LAN is 172.16.16.0/24 (Test If)

While the incoming request is seen, it seem like the outgoing reply is NATed separately with a wrong source port:

Code: [Select]
16:01:11.446958 IP 109.41.1.5.14631 > 192.168.254.2.8080: Flags [S], seq 568671719, win 14600, options [mss 1460,sackOK,TS val 460198899 ecr 0,nop,wscale 9], length 0
16:01:11.447756 IP 192.168.254.2.38922 > 109.41.1.5.14631: Flags [S.], seq 415419811, ack 568671720, win 14480, options [mss 1460,sackOK,TS val 190102564 ecr 460198899,nop,wscale 7], length 0
16:01:12.446936 IP 109.41.1.5.14631 > 192.168.254.2.8080: Flags [S], seq 568671719, win 14600, options [mss 1460,sackOK,TS val 460199899 ecr 0,nop,wscale 9], length 0
16:01:12.447656 IP 192.168.254.2.38922 > 109.41.1.5.14631: Flags [S.], seq 415419811, ack 568671720, win 14480, options [mss 1460,sackOK,TS val 190103563 ecr 460198899,nop,wscale 7], length 0
16:01:12.447755 IP 192.168.254.2.38922 > 109.41.1.5.14631: Flags [S.], seq 415419811, ack 568671720, win 14480, options [mss 1460,sackOK,TS val 190103564 ecr 460198899,nop,wscale 7], length 0
16:01:14.447865 IP 192.168.254.2.38922 > 109.41.1.5.14631: Flags [S.], seq 415419811, ack 568671720, win 14480, options [mss 1460,sackOK,TS val 190105564 ecr 460198899,nop,wscale 7], length 0

Hence, the connection never establishes.

Any idea how this could be misconfigured?
« Last Edit: June 12, 2018, 06:39:43 pm by namezero111111 »
Logged

namezero111111

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 10
    • View Profile
Re: Port Forward not working - reply with wrong source port?
« Reply #1 on: June 12, 2018, 06:39:30 pm »
The problem was an overlapping outbound NAT.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.1 Legacy Series »
  • [RESOLVED] Port Forward not working - reply with wrong source port?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2