
In the example we have opened port 51400.
Destination Port Range : We have to configure a range of ports or only one, if we want a range of ports, in the «From» we put a port, for example the 60000, and in the «To» we put the final port, the 61000. Protocol : we choose the protocol, in the example it is TCP. In this menu we will have different configuration options, but basically what we will have to fill in is the following: To open the NAT, the first thing we have to do is go to the “Firewall / NAT” section, and in the “Port forward” tab create a new rule. If you open ports in the NAT, but you have the CG-NAT of your operator, it will be of no use to you. If you have a NAS server with an FTP, VPN or SSH server, and you want to access all these services from the outside, you will have to open different ports in the NAT to allow starting the connection. When we are in a NAT environment, you may need to open ports to access certain services from the outside. On some occasions, such as Movistar / O2, we can put the router in single-user position and configure only the PPPoE, but on other occasions, such as Grupo Masmovil, we must configure a VLAN ID in the Internet WAN to work, otherwise, we will not have a connection to Internet.
In Spain, it is very common for FTTH operators to use different VLAN IDs to provide their connection to the Internet. PfSense is designed to connect directly to the Internet and have the public IP address provided by the operator, it is very important to have a public IP and not be behind CGNAT, otherwise, we will not be able to do port forwarding or remotely access pfSense itself. Therefore, to access the firewall and router administration, we must put in the address bar, the username is “admin” and the password is “pfsense”, thus we will directly access the configuration menu via the web, where we can see the following:
Access to administration is allowed by default. LAN: configured with 192.168.1.1/24 and with DHCP enabled.Access to the administration is not allowed by default. WAN: configured as DHCP client without VLANs or any additional configuration.