Jump to content

Welcome to ExtremeHW

Welcome to ExtremeHW, register to take part in our community, don't worry this is a simple FREE process that requires minimal information for you to signup.

 

Registered users can: 

  • Start new topics and reply to others.
  • Show off your PC using our Rig Creator feature.
  • Subscribe to topics and forums to get updates.
  • Get your own profile page to customize.
  • Send personal messages to other members.
  • Take advantage of site exclusive features.
  • Upgrade to Premium to unlock additional sites features.
IGNORED

OPNSense uPNP/ NAT issues


Recommended Posts

i have installed opnsense and am bridging through my ISP's provided modem for now (it does not dhcp lease or have wireless enabled)

 

the issue im having is ive installed the upnp plugin, rebooted it and when i run a game on my PC, it instant warns of STRICT NAT and doesnt allow me to session host.

 

the issues ive found are as follows :

 

- UPNP registers no ports when i connect to online portions of games

- setting a firewall rule to port forward through the NAT doesnt seem to function either

 

everything else is flawless, besides a little bit of speed loss between the modem and opnsense (like 50mbps, not much on 8gbps fiber)

 

im stumped and alot of games im playing im the session host for friends and have the game saves, so we're sort of SOL until i get this working.

 

any help is appreciated greatly. as im sure someone has knowledge i dont.

Owned

 Share

CPU: AMD R7 7800X3D
GPU: AMD RX Sapphire 7800XT Pure
MOTHERBOARD: MSI B650M Project Zero
RAM: Corsair Dominator Platinum 64GB 32-38-38 @ 6200mhz
SSD/NVME: Sabrent Rocket NVMe 500GB (Windows)
SSD/NVME 2: WD Black SN850X 4TB (Games)
SSD/NVME 3: Cruicial MX 500 2TB (Programs)
SSD/NVME 4: Crucial MX 300 1TB (Documents/Downloads)
Full Rig Info

Owned

 Share

CPU: Xeon 5345 @ 2.3GHZ
CPU 2: Xeon 5345 @ 2.3GHZ
MOTHERBOARD: Intel S5000PSL E-ATX
RAM: 32GB Hynix ECC DDR2 667Mhz
CPU COOLER: 2x Dynatron 2U Heatsinks
SSD/NVME: Samsung 840 EVO 120GB
HDD: Seagate Firecuda Compute 2TB
OPERATING SYSTEM: Winodws Server 2019 Standard
Full Rig Info
Link to comment
Share on other sites

On 08/01/2024 at 22:41, PCSarge said:

i have installed opnsense and am bridging through my ISP's provided modem for now (it does not dhcp lease or have wireless enabled)

 

the issue im having is ive installed the upnp plugin, rebooted it and when i run a game on my PC, it instant warns of STRICT NAT and doesnt allow me to session host.

 

the issues ive found are as follows :

 

- UPNP registers no ports when i connect to online portions of games

- setting a firewall rule to port forward through the NAT doesnt seem to function either

 

everything else is flawless, besides a little bit of speed loss between the modem and opnsense (like 50mbps, not much on 8gbps fiber)

 

im stumped and alot of games im playing im the session host for friends and have the game saves, so we're sort of SOL until i get this working.

 

any help is appreciated greatly. as im sure someone has knowledge i dont.

UPNP I find to be junk personally. Always manually forward ports if you can. 

 

I assume that you have forwarded the ports in your ISP router to the IP of your Firewall box, then in the Firewall box forwarded the same ports to your PC's static IP ?

 

You essentially have to forward the port traffic to your Firewall, and then forward it again to your PC. 

 

I also assumed your PC has a static IP ? Or bonded an IP to your MAC address ?

£3000

Owned

 Share

CPU: AMD Ryzen 9 7950X3D
MOTHERBOARD: MSI Meg Ace X670E
RAM: Corsair Dominator Titanium 64GB (6000MT/s)
GPU: EVGA 3090 FTW Ultra Gaming
SSD/NVME: Corsair MP700 Pro Gen 5 2TB
PSU: EVGA Supernova T2 1600Watt
CASE: be quiet Dark Base Pro 900 Rev 2
FANS: Noctua NF-A14 industrialPPC x 6
Full Rig Info

Owned

 Share

CPU: Intel Core i5 8500
RAM: 16GB (2x8GB) Kingston 2666Mhz
SSD/NVME: 256GB Samsung NVMe
NETWORK: HP 561T 10Gbe (Intel X540 T2)
MOTHERBOARD: Proprietry
GPU: Intel UHD Graphics 630
PSU: 90Watt
CASE: HP EliteDesk 800 G4 SFF
Full Rig Info

£3000

Owned

 Share

CPU: 2 x Xeon|E5-2696-V4 (44C/88T)
RAM: 128GB|16 x 8GB - DDR4 2400MHz (2Rx8)
MOTHERBOARD: HP Z840|Intel C612 Chipset
GPU: Nvidia Quadro P2200
HDD: 4x 16TB Toshiba MG08ACA16TE Enterprise
SSD/NVME: Intel 512GB 670p NVMe (Main OS)
SSD/NVME 2: Samsung 1TB 980 NVMe (VM's)
SSD/NVME 3: 2x Seagate FireCuda 1TB SSD's (Apps)
Full Rig Info
Link to comment
Share on other sites

7 hours ago, ENTERPRISE said:

UPNP I find to be junk personally. Always manually forward ports if you can. 

 

I assume that you have forwarded the ports in your ISP router to the IP of your Firewall box, then in the Firewall box forwarded the same ports to your PC's static IP ?

 

You essentially have to forward the port traffic to your Firewall, and then forward it again to your PC. 

 

I also assumed your PC has a static IP ? Or bonded an IP to your MAC address ?

the pc is is on a static IP, i have tried a few things including port forwarding, which got me down to moderate in some games and strict in others.

 

the ISP router is completely bypassed, it doesnt even see the pfsense box, as pfsense is using pppoe and connecting directly to internet service. which makes the ISP router basically a glorified conversion interface for the fiber line

Owned

 Share

CPU: AMD R7 7800X3D
GPU: AMD RX Sapphire 7800XT Pure
MOTHERBOARD: MSI B650M Project Zero
RAM: Corsair Dominator Platinum 64GB 32-38-38 @ 6200mhz
SSD/NVME: Sabrent Rocket NVMe 500GB (Windows)
SSD/NVME 2: WD Black SN850X 4TB (Games)
SSD/NVME 3: Cruicial MX 500 2TB (Programs)
SSD/NVME 4: Crucial MX 300 1TB (Documents/Downloads)
Full Rig Info

Owned

 Share

CPU: Xeon 5345 @ 2.3GHZ
CPU 2: Xeon 5345 @ 2.3GHZ
MOTHERBOARD: Intel S5000PSL E-ATX
RAM: 32GB Hynix ECC DDR2 667Mhz
CPU COOLER: 2x Dynatron 2U Heatsinks
SSD/NVME: Samsung 840 EVO 120GB
HDD: Seagate Firecuda Compute 2TB
OPERATING SYSTEM: Winodws Server 2019 Standard
Full Rig Info
Link to comment
Share on other sites

8 hours ago, PCSarge said:

the pc is is on a static IP, i have tried a few things including port forwarding, which got me down to moderate in some games and strict in others.

 

the ISP router is completely bypassed, it doesnt even see the pfsense box, as pfsense is using pppoe and connecting directly to internet service. which makes the ISP router basically a glorified conversion interface for the fiber line

 

Well the only thing I can think of at the moment is the ISP router is still either interfering, which you can fix by configuring the ISP router to put your Firewall Device in the DMZ, which means the ISP router will ignore your Firewall device completely regarding any security protocols and will auto forward all traffic.

 

Other than that, it has been known that CGNAT can cause issues with port forwarding. It is possible that your ISP uses CGNAT.

 

HELP.BRSK.CO.UK

A technical article on what CGNAT is and its uses

 

  • Great Idea 1

£3000

Owned

 Share

CPU: AMD Ryzen 9 7950X3D
MOTHERBOARD: MSI Meg Ace X670E
RAM: Corsair Dominator Titanium 64GB (6000MT/s)
GPU: EVGA 3090 FTW Ultra Gaming
SSD/NVME: Corsair MP700 Pro Gen 5 2TB
PSU: EVGA Supernova T2 1600Watt
CASE: be quiet Dark Base Pro 900 Rev 2
FANS: Noctua NF-A14 industrialPPC x 6
Full Rig Info

Owned

 Share

CPU: Intel Core i5 8500
RAM: 16GB (2x8GB) Kingston 2666Mhz
SSD/NVME: 256GB Samsung NVMe
NETWORK: HP 561T 10Gbe (Intel X540 T2)
MOTHERBOARD: Proprietry
GPU: Intel UHD Graphics 630
PSU: 90Watt
CASE: HP EliteDesk 800 G4 SFF
Full Rig Info

£3000

Owned

 Share

CPU: 2 x Xeon|E5-2696-V4 (44C/88T)
RAM: 128GB|16 x 8GB - DDR4 2400MHz (2Rx8)
MOTHERBOARD: HP Z840|Intel C612 Chipset
GPU: Nvidia Quadro P2200
HDD: 4x 16TB Toshiba MG08ACA16TE Enterprise
SSD/NVME: Intel 512GB 670p NVMe (Main OS)
SSD/NVME 2: Samsung 1TB 980 NVMe (VM's)
SSD/NVME 3: 2x Seagate FireCuda 1TB SSD's (Apps)
Full Rig Info
Link to comment
Share on other sites

This was the same reason I went away from OPNsense on mine.  I do not have a solution, just sharing that I've faced the same problem before of port forwarding not working / UPNP not working correctly on OPNsense.

Owned

 Share

CPU: Ryzen 7900x
GPU: Sapphire Pulse RX 7900XTX
PSU: Cooler Master 850w Platinum
CPU COOLER: Cooler Master MasterLiquid PL360 Flux
MOTHERBOARD: Gigabyte B650 Aorus AX
SSD/NVME: Solidigm P41 Plus 2TB Gen4 NVME
RAM: G.Skill Flare X DDR5-6000
CASE: HAF700 Berserker
Full Rig Info

Too much

Owned

 Share

CPU: AMD Opteron 180 @ 3.0GHz
MOTHERBOARD: Asus A8N SLI
RAM: 4x1GB Corsair XMS DDR400 @ 2.5-3-3-6
PSU: eVGA 600BQ
GPU: Sapphire HD5870
SOUNDCARD: Asus Xonar DG
OPTICAL: DVDRW with Lightscribe
SSD/NVME: 64GB HP 2.5" SSD
Full Rig Info

Too much

Owned

 Share

CPU: AMD Athlon 1100MHz
MOTHERBOARD: ECS K7S5A
RAM: 2x256MB Corsair XMS DDR400 @ 133MHz / CAS2
PSU: Antec 350w
GPU: ATI Radeon 9800 PRO
SOUNDCARD: Creative Live! 5.1
OPTICAL: LG 16x DVD-ROM
OPTICAL 2: IOMagic 48x16x48 CDRW
Full Rig Info
Link to comment
Share on other sites

12 hours ago, pioneerisloud said:

This was the same reason I went away from OPNsense on mine.  I do not have a solution, just sharing that I've faced the same problem before of port forwarding not working / UPNP not working correctly on OPNsense.

 

All I can saw is port forwarding works flawlessly with my setup, ISP Router forwards traffic to my PfSense FW and then my PfSense FW forwards the traffic on to my actual devices. It is possible CGNAT is the issue or something related to PPPOE, though I cannot see how the PPPOE would make any difference.

  • Respect 1

£3000

Owned

 Share

CPU: AMD Ryzen 9 7950X3D
MOTHERBOARD: MSI Meg Ace X670E
RAM: Corsair Dominator Titanium 64GB (6000MT/s)
GPU: EVGA 3090 FTW Ultra Gaming
SSD/NVME: Corsair MP700 Pro Gen 5 2TB
PSU: EVGA Supernova T2 1600Watt
CASE: be quiet Dark Base Pro 900 Rev 2
FANS: Noctua NF-A14 industrialPPC x 6
Full Rig Info

Owned

 Share

CPU: Intel Core i5 8500
RAM: 16GB (2x8GB) Kingston 2666Mhz
SSD/NVME: 256GB Samsung NVMe
NETWORK: HP 561T 10Gbe (Intel X540 T2)
MOTHERBOARD: Proprietry
GPU: Intel UHD Graphics 630
PSU: 90Watt
CASE: HP EliteDesk 800 G4 SFF
Full Rig Info

£3000

Owned

 Share

CPU: 2 x Xeon|E5-2696-V4 (44C/88T)
RAM: 128GB|16 x 8GB - DDR4 2400MHz (2Rx8)
MOTHERBOARD: HP Z840|Intel C612 Chipset
GPU: Nvidia Quadro P2200
HDD: 4x 16TB Toshiba MG08ACA16TE Enterprise
SSD/NVME: Intel 512GB 670p NVMe (Main OS)
SSD/NVME 2: Samsung 1TB 980 NVMe (VM's)
SSD/NVME 3: 2x Seagate FireCuda 1TB SSD's (Apps)
Full Rig Info
Link to comment
Share on other sites

My approach would be to use wireshark to figure out what ports are needed, and nmap to see if those ports are actually open.  Chances are they aren't and your ISP router is still in play.

 

Setting the pfsense to demilitarized from your ISP router is a reasonable solution, that should eliminate the isp router as a problem.

 

In my previous experiences with this, the ISP router was still in play and the ports from it had to be forwarded as well.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×
×
  • Create New...

Important Information

This Website may place and access certain Cookies on your computer. ExtremeHW uses Cookies to improve your experience of using the Website and to improve our range of products and services. ExtremeHW has carefully chosen these Cookies and has taken steps to ensure that your privacy is protected and respected at all times. All Cookies used by this Website are used in accordance with current UK and EU Cookie Law. For more information please see our Privacy Policy