Jump to content

PfSense DMZ/NAT Help

TubsAlwaysWins

Ok so can someone please show me how to set up a DMZ interface on PfSense V2.3.1 (Or the NAT)I need it for a PS4 and NAT wont do anything, but DMZ worked on my other router (Linksys WRT1900AC, gets less than half of PFSenses speed). Please tell me where to click. Online guides are usually outdated and confusing. Thank you

 

Breaking things 1 day at a time

Link to comment
Share on other sites

Link to post
Share on other sites

47 minutes ago, TubsAlwaysWins said:

Ok so can someone please show me how to set up a DMZ interface on PfSense V2.3.1? I need it for a PS4 and NAT wont do anything, but DMZ worked on my other router (Linksys WRT1900AC, gets less than half of PFSenses speed). Please tell me where to click. Online guides are usually outdated and confusing. Thank you

well, there is google... 

https://www.google.com/search?q=what+is+DMZ&oq=what+is+DMZ&aqs=chrome..69i57j0l5.4235j0j7&sourceid=chrome&ie=UTF-8#safe=strict&q=DMZ+setup+pfsense

Fine you want the PSU tier list? Have the PSU tier list: https://linustechtips.com/main/topic/1116640-psu-tier-list-40-rev-103/

 

Stille (Desktop)

Ryzen 9 3900XT@4.5Ghz - Cryorig H7 Ultimate - 16GB Vengeance LPX 3000Mhz- MSI RTX 3080 Ti Ventus 3x OC - SanDisk Plus 480GB - Crucial MX500 500GB - Intel 660P 1TB SSD - (2x) WD Red 2TB - EVGA G3 650w - Corsair 760T

Evoo Gaming 15"
i7-9750H - 16GB DDR4 - GTX 1660Ti - 480GB SSD M.2 - 1TB 2.5" BX500 SSD 

VM + NAS Server (ProxMox 6.3)

1x Xeon E5-2690 v2  - 92GB ECC DDR3 - Quadro 4000 - Dell H310 HBA (Flashed with IT firmware) -500GB Crucial MX500 (Proxmox Host) Kingston 128GB SSD (FreeNAS dev/ID passthrough) - 8x4TB Toshiba N300 HDD

Toys: Ender 3 Pro, Oculus Rift CV1, Oculus Quest 2, about half a dozen raspberry Pis (2b to 4), Arduino Uno, Arduino Mega, Arduino nano (x3), Arduino nano pro, Atomic Pi. 

Link to comment
Share on other sites

Link to post
Share on other sites

12 hours ago, Brink2Three said:

Doesnt help. Tried that 3 times. I clicked on the first 5 results before you sent me that link. ANd every guide on that list is for a much older version of PFSense, and I dont have some of the buttons they have. If I did I wouldnt be asking this question

 

Breaking things 1 day at a time

Link to comment
Share on other sites

Link to post
Share on other sites

Rather than doing a DMZ, you could just try forwarding the following ports to your PS4.

 

  • TCP: 80, 443, 1935, 3478-3480
  • UDP: 3478-3479

According to my web search these are the ones that you need to make a PS4 happy with it's internet connection. 

Link to comment
Share on other sites

Link to post
Share on other sites

I don't see why a real DMZ is required for a PS4?

Many consumer grade routers call an exposed host a DMZ which is totally wrong.

So maybe you are a bit confused about what a DMZ is.

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, AdmnPower said:

Rather than doing a DMZ, you could just try forwarding the following ports to your PS4.

 

  • TCP: 80, 443, 1935, 3478-3480
  • UDP: 3478-3479

According to my web search these are the ones that you need to make a PS4 happy with it's internet connection. 

I dont think my ISP allows Port Forwarding. (Hilltop Wireless)

http://hilltop-broadband.com/index.html

I had all of those ports forwarded and I still had NAT Type 3

 

 

Breaking things 1 day at a time

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, TubsAlwaysWins said:

I dont think my ISP allows Port Forwarding. (Hilltop Wireless)

http://hilltop-broadband.com/index.html

I had all of those ports forwarded and I still had NAT Type 3

 

He's saying to do the port forwarding in pfsense so that when NAT happens, it forwards those ports to the PS4. Your ISP cannot prevent that kind of port forwarding from happening, since it happens at the NAT level, not at the ISP level.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, dalekphalm said:

He's saying to do the port forwarding in pfsense so that when NAT happens, it forwards those ports to the PS4. Your ISP cannot prevent that kind of port forwarding from happening, since it happens at the NAT level, not at the ISP level.

If there's CGN you can not forward a port

Link to comment
Share on other sites

Link to post
Share on other sites

12 hours ago, dalekphalm said:

He's saying to do the port forwarding in pfsense so that when NAT happens, it forwards those ports to the PS4. Your ISP cannot prevent that kind of port forwarding from happening, since it happens at the NAT level, not at the ISP level.

I'm not familiar with Hilltop Wireless but if it's like most other wireless providers odds are OP doesn't have a true public IP address which would explain why port forwards don't fix the problem. Can you check and see what IP address is on the WAN port of your pFsense box? That'll answer the question for us so we can figure out maybe what to do next. 

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, AdmnPower said:

I'm not familiar with Hilltop Wireless but if it's like most other wireless providers odds are OP doesn't have a true public IP address which would explain why port forwards don't fix the problem. Can you check and see what IP address is on the WAN port of your pFsense box? That'll answer the question for us so we can figure out maybe what to do next. 

My way around the problem was I used a switch and ran my ISP line into the switch. Then it goes out to mmy PS4 and out to my Router, so my PS4 snit om a router.

WAN Address is 192.168.100.36

 

Breaking things 1 day at a time

Link to comment
Share on other sites

Link to post
Share on other sites

Sounds like a reasonable enough solution to me as it avoids the double NAT problem you were having. 192.168.100.36 is definately a private address so that does really limit what you can do. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×