[pfSense Support] problem using c panel

2010-05-11 Thread khairil
hye
my company is using pfsense for routing and firewall.the problem is we are
hosting a an outsorce email server for one of our department.internal user are
not allowed to access to one of our ftp.But i have bypass the port from pfsense
and its working okay.How i want to add port than can make we access it easily. 


-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



[pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Chris Flugstad
So I have a pfsense router in a buidling DHCP'ing pub ip's on the LAN.  
I have a user that can connect his xbox 360 online to xbox live but 
cannot connect to other players or join parties.  He has tried plugging 
his xbox directly bypassing his router and giving his xbox a pub ip.  
this does not work.  i wonder if something would need to be set in 
pfsense to allow this to work?


Again, I have public ip's on the inside of my network so i do not have 
NAT for any of you who are going to respond with responses that would 
point me into doing fw changes for NAT


below is a dump of my config.

Sincerely,
Topher



?xml version=1.0?
pfsense
version3.0/version
lastchange/
themenervecenter/theme
system
optimizationnormal/optimization
hostname /hostname
domain .net/domain
username /username
password$./password
timezoneEtc/GMT-8/timezone
time-update-interval/
timeservers0.pfsense.pool.ntp.org/timeservers
webgui
protocolhttps/protocol
port/
certificate/
private-key/
/webgui
disablenatreflectionyes/disablenatreflection
ssh
authorizedkeys/
port/
/ssh
enablesshdyes/enablesshd
maximumstates/
shapertype/
dnsserver207.66.128.8/dnsserver
dnsserver207.66.60.8/dnsserver
dnsallowoverride/
/system
interfaces
lan
ifbge0/if
ipaddr216.127.63.65/ipaddr
subnet26/subnet
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
bridge/
/lan
wan
ifbge1/if
mtu/
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
spoofmac/
ipaddr216.127.32.44/ipaddr
subnet29/subnet
gateway216.127.32.41/gateway
/wan
/interfaces
staticroutes/
pppoe
username/
password/
provider/
/pppoe
pptp
username/
password/
local/
subnet/
remote/
/pptp
bigpond/
dyndns
typedyndns/type
username/
password/
host/
mx/
/dyndns
dhcpd
lan
enable/
range
from216.127.63.66/from
to216.127.63.126/to
/range
defaultleasetime/
maxleasetime/
netmask/
failover_peerip/
gateway216.127.63.65/gateway
ddnsdomain/
next-server/
filename/
staticmap
mac00:21:91:15:90:24/mac
ipaddr216.127.63.80/ipaddr
hostnameWBR-1310/hostname
descr/
/staticmap
/lan
/dhcpd
pptpd
mode/
redir/
localip/
remoteip/
/pptpd
ovpn/
dnsmasq
enable/
/dnsmasq
snmpd
syslocation/
syscontact/
rocommunitypublic/rocommunity
/snmpd
diag
ipv6nat/
/diag
bridge/
syslog/
nat
ipsecpassthru/
advancedoutbound
enable/
/advancedoutbound
/nat
filter
rule
typeblock/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/os
source
address216.127.63.80/address
/source
destination
any/
/destination
descr/
/rule
rule
typepass/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
any/
/source
destination
any/
/destination
descr/
/rule
rule
typereject/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.80/address
/source
destination
any/
/destination
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.116/address
/source
destination
any/
/destination
disabled/
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.100/address
/source
destination
any/
/destination
descr/
disabled/
/rule
rule
typepass/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
networklan/network
/source
destination
any/
/destination
descrDefault LAN -gt; any/descr
/rule
/filter
ipsec
preferredoldsa/
/ipsec
aliases
alias
namemischeif/name
address216.127.63.80/address
descrbad peoplos/descr
typehost/type
detailEntry added Mon, 18 Jan 2010 16:57:58 +0800||/detail
/alias
/aliases
proxyarp/
cron
item
minute0/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 newsyslog/command
/item
item
minute1,31/minute
hour0-5/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 adjkerntz -a/command
/item
item
minute1/minute
hour3/hour
mday1/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /etc/rc.update_bogons.sh/command
/item
item
minute*/60/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 
sshlockout/command

/item
item
minute1/minute
hour1/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /etc/rc.dyndns.update/command
/item
item
minute*/60/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 
virusprot/command

/item
item
minute*/60/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 3600 
snort2c/command

/item
item
minute*/5/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who

Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Gary Buckmaster
I'm using an XBox behind a very straightforward pfSense install without 
any difficulty.  You shouldn't need any special contortions to make it 
work except NATing the ports XBox Live wants (it works without them but 
it complains).  UPnP should also Just Work if you enable that. 


Chris Flugstad wrote:
So I have a pfsense router in a buidling DHCP'ing pub ip's on the 
LAN.  I have a user that can connect his xbox 360 online to xbox live 
but cannot connect to other players or join parties.  He has tried 
plugging his xbox directly bypassing his router and giving his xbox a 
pub ip.  this does not work.  i wonder if something would need to be 
set in pfsense to allow this to work?


Again, I have public ip's on the inside of my network so i do not have 
NAT for any of you who are going to respond with responses that would 
point me into doing fw changes for NAT


below is a dump of my config.

Sincerely,
Topher



?xml version=1.0?
pfsense
version3.0/version
lastchange/
themenervecenter/theme
system
optimizationnormal/optimization
hostname /hostname
domain .net/domain
username /username
password$./password
timezoneEtc/GMT-8/timezone
time-update-interval/
timeservers0.pfsense.pool.ntp.org/timeservers
webgui
protocolhttps/protocol
port/
certificate/
private-key/
/webgui
disablenatreflectionyes/disablenatreflection
ssh
authorizedkeys/
port/
/ssh
enablesshdyes/enablesshd
maximumstates/
shapertype/
dnsserver207.66.128.8/dnsserver
dnsserver207.66.60.8/dnsserver
dnsallowoverride/
/system
interfaces
lan
ifbge0/if
ipaddr216.127.63.65/ipaddr
subnet26/subnet
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
bridge/
/lan
wan
ifbge1/if
mtu/
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
spoofmac/
ipaddr216.127.32.44/ipaddr
subnet29/subnet
gateway216.127.32.41/gateway
/wan
/interfaces
staticroutes/
pppoe
username/
password/
provider/
/pppoe
pptp
username/
password/
local/
subnet/
remote/
/pptp
bigpond/
dyndns
typedyndns/type
username/
password/
host/
mx/
/dyndns
dhcpd
lan
enable/
range
from216.127.63.66/from
to216.127.63.126/to
/range
defaultleasetime/
maxleasetime/
netmask/
failover_peerip/
gateway216.127.63.65/gateway
ddnsdomain/
next-server/
filename/
staticmap
mac00:21:91:15:90:24/mac
ipaddr216.127.63.80/ipaddr
hostnameWBR-1310/hostname
descr/
/staticmap
/lan
/dhcpd
pptpd
mode/
redir/
localip/
remoteip/
/pptpd
ovpn/
dnsmasq
enable/
/dnsmasq
snmpd
syslocation/
syscontact/
rocommunitypublic/rocommunity
/snmpd
diag
ipv6nat/
/diag
bridge/
syslog/
nat
ipsecpassthru/
advancedoutbound
enable/
/advancedoutbound
/nat
filter
rule
typeblock/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/os
source
address216.127.63.80/address
/source
destination
any/
/destination
descr/
/rule
rule
typepass/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
any/
/source
destination
any/
/destination
descr/
/rule
rule
typereject/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.80/address
/source
destination
any/
/destination
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.116/address
/source
destination
any/
/destination
disabled/
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.100/address
/source
destination
any/
/destination
descr/
disabled/
/rule
rule
typepass/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
networklan/network
/source
destination
any/
/destination
descrDefault LAN -gt; any/descr
/rule
/filter
ipsec
preferredoldsa/
/ipsec
aliases
alias
namemischeif/name
address216.127.63.80/address
descrbad peoplos/descr
typehost/type
detailEntry added Mon, 18 Jan 2010 16:57:58 +0800||/detail
/alias
/aliases
proxyarp/
cron
item
minute0/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 newsyslog/command
/item
item
minute1,31/minute
hour0-5/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 adjkerntz -a/command
/item
item
minute1/minute
hour3/hour
mday1/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /etc/rc.update_bogons.sh/command
/item
item
minute*/60/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 
sshlockout/command

/item
item
minute1/minute
hour1/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /etc/rc.dyndns.update/command
/item
item
minute*/60/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 

Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Chris Flugstad
I totally knew I'd get a response in regards to NATing ;)  I am not 
using NAT.  I have public ip's on the inside of this network so there is 
no NATING.  UPNP would only be used for NAT  correct?
I myself tend to skim posts on here, so I totally understand Gary, and 
thanks for the quick response.  Hopefully someone else has a response 
that will help though.


-topher

On 5/11/2010 5:23 PM, Gary Buckmaster wrote:
I'm using an XBox behind a very straightforward pfSense install 
without any difficulty.  You shouldn't need any special contortions to 
make it work except NATing the ports XBox Live wants (it works without 
them but it complains).  UPnP should also Just Work if you enable that.

Chris Flugstad wrote:
So I have a pfsense router in a buidling DHCP'ing pub ip's on the 
LAN.  I have a user that can connect his xbox 360 online to xbox live 
but cannot connect to other players or join parties.  He has tried 
plugging his xbox directly bypassing his router and giving his xbox a 
pub ip.  this does not work.  i wonder if something would need to be 
set in pfsense to allow this to work?


Again, I have public ip's on the inside of my network so i do not 
have NAT for any of you who are going to respond with responses that 
would point me into doing fw changes for NAT


below is a dump of my config.

Sincerely,
Topher



?xml version=1.0?
pfsense
version3.0/version
lastchange/
themenervecenter/theme
system
optimizationnormal/optimization
hostname /hostname
domain .net/domain
username /username
password$./password
timezoneEtc/GMT-8/timezone
time-update-interval/
timeservers0.pfsense.pool.ntp.org/timeservers
webgui
protocolhttps/protocol
port/
certificate/
private-key/
/webgui
disablenatreflectionyes/disablenatreflection
ssh
authorizedkeys/
port/
/ssh
enablesshdyes/enablesshd
maximumstates/
shapertype/
dnsserver207.66.128.8/dnsserver
dnsserver207.66.60.8/dnsserver
dnsallowoverride/
/system
interfaces
lan
ifbge0/if
ipaddr216.127.63.65/ipaddr
subnet26/subnet
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
bridge/
/lan
wan
ifbge1/if
mtu/
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
spoofmac/
ipaddr216.127.32.44/ipaddr
subnet29/subnet
gateway216.127.32.41/gateway
/wan
/interfaces
staticroutes/
pppoe
username/
password/
provider/
/pppoe
pptp
username/
password/
local/
subnet/
remote/
/pptp
bigpond/
dyndns
typedyndns/type
username/
password/
host/
mx/
/dyndns
dhcpd
lan
enable/
range
from216.127.63.66/from
to216.127.63.126/to
/range
defaultleasetime/
maxleasetime/
netmask/
failover_peerip/
gateway216.127.63.65/gateway
ddnsdomain/
next-server/
filename/
staticmap
mac00:21:91:15:90:24/mac
ipaddr216.127.63.80/ipaddr
hostnameWBR-1310/hostname
descr/
/staticmap
/lan
/dhcpd
pptpd
mode/
redir/
localip/
remoteip/
/pptpd
ovpn/
dnsmasq
enable/
/dnsmasq
snmpd
syslocation/
syscontact/
rocommunitypublic/rocommunity
/snmpd
diag
ipv6nat/
/diag
bridge/
syslog/
nat
ipsecpassthru/
advancedoutbound
enable/
/advancedoutbound
/nat
filter
rule
typeblock/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/os
source
address216.127.63.80/address
/source
destination
any/
/destination
descr/
/rule
rule
typepass/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
any/
/source
destination
any/
/destination
descr/
/rule
rule
typereject/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.80/address
/source
destination
any/
/destination
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.116/address
/source
destination
any/
/destination
disabled/
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.100/address
/source
destination
any/
/destination
descr/
disabled/
/rule
rule
typepass/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
networklan/network
/source
destination
any/
/destination
descrDefault LAN -gt; any/descr
/rule
/filter
ipsec
preferredoldsa/
/ipsec
aliases
alias
namemischeif/name
address216.127.63.80/address
descrbad peoplos/descr
typehost/type
detailEntry added Mon, 18 Jan 2010 16:57:58 +0800||/detail
/alias
/aliases
proxyarp/
cron
item
minute0/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 newsyslog/command
/item
item
minute1,31/minute
hour0-5/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 adjkerntz -a/command
/item
item
minute1/minute
hour3/hour
mday1/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 /etc/rc.update_bogons.sh/command
/item
item
minute*/60/minute
hour*/hour
mday*/mday

Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Chris Buechler
On Tue, May 11, 2010 at 8:37 PM, Chris Flugstad ch...@cascadelink.com wrote:
 I totally knew I'd get a response in regards to NATing ;)  I am not using
 NAT.  I have public ip's on the inside of this network so there is no
 NATING.  UPNP would only be used for NAT  correct?

Yeah. As long as you have a wide open ruleset, you don't need to do
anything else.

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Gary Buckmaster
My point wasn't that you need NAT, I got the part where you said you 
weren't NATing.  The point is that no special configurations are needed 
to make XBox live work with pfSense and yes, UPnP is simply to 
automagically set up NATs as needed. 


Chris Flugstad wrote:
I totally knew I'd get a response in regards to NATing ;)  I am not 
using NAT.  I have public ip's on the inside of this network so there 
is no NATING.  UPNP would only be used for NAT  correct?
I myself tend to skim posts on here, so I totally understand Gary, and 
thanks for the quick response.  Hopefully someone else has a response 
that will help though.


-topher

On 5/11/2010 5:23 PM, Gary Buckmaster wrote:
I'm using an XBox behind a very straightforward pfSense install 
without any difficulty.  You shouldn't need any special contortions 
to make it work except NATing the ports XBox Live wants (it works 
without them but it complains).  UPnP should also Just Work if you 
enable that.

Chris Flugstad wrote:
So I have a pfsense router in a buidling DHCP'ing pub ip's on the 
LAN.  I have a user that can connect his xbox 360 online to xbox 
live but cannot connect to other players or join parties.  He has 
tried plugging his xbox directly bypassing his router and giving his 
xbox a pub ip.  this does not work.  i wonder if something would 
need to be set in pfsense to allow this to work?


Again, I have public ip's on the inside of my network so i do not 
have NAT for any of you who are going to respond with responses that 
would point me into doing fw changes for NAT


below is a dump of my config.

Sincerely,
Topher



?xml version=1.0?
pfsense
version3.0/version
lastchange/
themenervecenter/theme
system
optimizationnormal/optimization
hostname /hostname
domain .net/domain
username /username
password$./password
timezoneEtc/GMT-8/timezone
time-update-interval/
timeservers0.pfsense.pool.ntp.org/timeservers
webgui
protocolhttps/protocol
port/
certificate/
private-key/
/webgui
disablenatreflectionyes/disablenatreflection
ssh
authorizedkeys/
port/
/ssh
enablesshdyes/enablesshd
maximumstates/
shapertype/
dnsserver207.66.128.8/dnsserver
dnsserver207.66.60.8/dnsserver
dnsallowoverride/
/system
interfaces
lan
ifbge0/if
ipaddr216.127.63.65/ipaddr
subnet26/subnet
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
bridge/
/lan
wan
ifbge1/if
mtu/
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
spoofmac/
ipaddr216.127.32.44/ipaddr
subnet29/subnet
gateway216.127.32.41/gateway
/wan
/interfaces
staticroutes/
pppoe
username/
password/
provider/
/pppoe
pptp
username/
password/
local/
subnet/
remote/
/pptp
bigpond/
dyndns
typedyndns/type
username/
password/
host/
mx/
/dyndns
dhcpd
lan
enable/
range
from216.127.63.66/from
to216.127.63.126/to
/range
defaultleasetime/
maxleasetime/
netmask/
failover_peerip/
gateway216.127.63.65/gateway
ddnsdomain/
next-server/
filename/
staticmap
mac00:21:91:15:90:24/mac
ipaddr216.127.63.80/ipaddr
hostnameWBR-1310/hostname
descr/
/staticmap
/lan
/dhcpd
pptpd
mode/
redir/
localip/
remoteip/
/pptpd
ovpn/
dnsmasq
enable/
/dnsmasq
snmpd
syslocation/
syscontact/
rocommunitypublic/rocommunity
/snmpd
diag
ipv6nat/
/diag
bridge/
syslog/
nat
ipsecpassthru/
advancedoutbound
enable/
/advancedoutbound
/nat
filter
rule
typeblock/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/os
source
address216.127.63.80/address
/source
destination
any/
/destination
descr/
/rule
rule
typepass/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
any/
/source
destination
any/
/destination
descr/
/rule
rule
typereject/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.80/address
/source
destination
any/
/destination
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.116/address
/source
destination
any/
/destination
disabled/
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.100/address
/source
destination
any/
/destination
descr/
disabled/
/rule
rule
typepass/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
networklan/network
/source
destination
any/
/destination
descrDefault LAN -gt; any/descr
/rule
/filter
ipsec
preferredoldsa/
/ipsec
aliases
alias
namemischeif/name
address216.127.63.80/address
descrbad peoplos/descr
typehost/type
detailEntry added Mon, 18 Jan 2010 16:57:58 +0800||/detail
/alias
/aliases
proxyarp/
cron
item
minute0/minute
hour*/hour
mday*/mday
month*/month
wday*/wday
whoroot/who
command/usr/bin/nice -n20 newsyslog/command
/item
item
minute1,31/minute
hour0-5/hour
mday*/mday

Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-11 Thread Chris Flugstad

Cool.

I didnt think anything special would have to be done. Its prolly a 
personal problem that the client isn't hookin up with there freinds on 
xbox live.  i havent a clue. never had a problem like this before


thanks gary.

if this raises an eyebrow to anyone on why there would be a problem, do 
tell, as Gary and myself both agree that there isnt anything that I 
should have to do in pfsense to make this work.


-topher

On 5/11/2010 6:09 PM, Gary Buckmaster wrote:
My point wasn't that you need NAT, I got the part where you said you 
weren't NATing.  The point is that no special configurations are 
needed to make XBox live work with pfSense and yes, UPnP is simply to 
automagically set up NATs as needed.

Chris Flugstad wrote:
I totally knew I'd get a response in regards to NATing ;)  I am not 
using NAT.  I have public ip's on the inside of this network so there 
is no NATING.  UPNP would only be used for NAT  correct?
I myself tend to skim posts on here, so I totally understand Gary, 
and thanks for the quick response.  Hopefully someone else has a 
response that will help though.


-topher

On 5/11/2010 5:23 PM, Gary Buckmaster wrote:
I'm using an XBox behind a very straightforward pfSense install 
without any difficulty.  You shouldn't need any special contortions 
to make it work except NATing the ports XBox Live wants (it works 
without them but it complains).  UPnP should also Just Work if you 
enable that.

Chris Flugstad wrote:
So I have a pfsense router in a buidling DHCP'ing pub ip's on the 
LAN.  I have a user that can connect his xbox 360 online to xbox 
live but cannot connect to other players or join parties.  He has 
tried plugging his xbox directly bypassing his router and giving 
his xbox a pub ip.  this does not work.  i wonder if something 
would need to be set in pfsense to allow this to work?


Again, I have public ip's on the inside of my network so i do not 
have NAT for any of you who are going to respond with responses 
that would point me into doing fw changes for NAT


below is a dump of my config.

Sincerely,
Topher



?xml version=1.0?
pfsense
version3.0/version
lastchange/
themenervecenter/theme
system
optimizationnormal/optimization
hostname /hostname
domain .net/domain
username /username
password$./password
timezoneEtc/GMT-8/timezone
time-update-interval/
timeservers0.pfsense.pool.ntp.org/timeservers
webgui
protocolhttps/protocol
port/
certificate/
private-key/
/webgui
disablenatreflectionyes/disablenatreflection
ssh
authorizedkeys/
port/
/ssh
enablesshdyes/enablesshd
maximumstates/
shapertype/
dnsserver207.66.128.8/dnsserver
dnsserver207.66.60.8/dnsserver
dnsallowoverride/
/system
interfaces
lan
ifbge0/if
ipaddr216.127.63.65/ipaddr
subnet26/subnet
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
bridge/
/lan
wan
ifbge1/if
mtu/
media/
mediaopt/
bandwidth100/bandwidth
bandwidthtypeMb/bandwidthtype
spoofmac/
ipaddr216.127.32.44/ipaddr
subnet29/subnet
gateway216.127.32.41/gateway
/wan
/interfaces
staticroutes/
pppoe
username/
password/
provider/
/pppoe
pptp
username/
password/
local/
subnet/
remote/
/pptp
bigpond/
dyndns
typedyndns/type
username/
password/
host/
mx/
/dyndns
dhcpd
lan
enable/
range
from216.127.63.66/from
to216.127.63.126/to
/range
defaultleasetime/
maxleasetime/
netmask/
failover_peerip/
gateway216.127.63.65/gateway
ddnsdomain/
next-server/
filename/
staticmap
mac00:21:91:15:90:24/mac
ipaddr216.127.63.80/ipaddr
hostnameWBR-1310/hostname
descr/
/staticmap
/lan
/dhcpd
pptpd
mode/
redir/
localip/
remoteip/
/pptpd
ovpn/
dnsmasq
enable/
/dnsmasq
snmpd
syslocation/
syscontact/
rocommunitypublic/rocommunity
/snmpd
diag
ipv6nat/
/diag
bridge/
syslog/
nat
ipsecpassthru/
advancedoutbound
enable/
/advancedoutbound
/nat
filter
rule
typeblock/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/os
source
address216.127.63.80/address
/source
destination
any/
/destination
descr/
/rule
rule
typepass/type
interfacewan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
any/
/source
destination
any/
/destination
descr/
/rule
rule
typereject/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.80/address
/source
destination
any/
/destination
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.116/address
/source
destination
any/
/destination
disabled/
descrblock misch ip/descr
/rule
rule
typeblock/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
address216.127.63.100/address
/source
destination
any/
/destination
descr/
disabled/
/rule
rule
typepass/type
interfacelan/interface
max-src-nodes/
max-src-states/
statetimeout/
statetypekeep state/statetype
os/
source
networklan/network
/source