Xbox 360 Behind pfSense Firewall: Your NAT Type Is Strict
Posted by alex in Insights at 6:27 PMWe recently put a Xbox 360 online at the computer shop and I finally got around to configuring everything so we could get on Xbox Live. Our network uses a pfSense firewall along with some other security measures which create a fairly secure environment however it can take some configuration to get things working properly at times. The pfSense firewall is a really amazing open source firewall software developed by some folks here in Louisville. Anyhow depending on how your firewall is set up you may run into a couple issues, which aren’t really issues, connecting to Xbox Live. Below is information on how to get past your Xbox 360 reporting that the NAT type is Strict when your Xbox 360 is located behind a pfSense firewall.
Xbox 360: Your NAT Type Is Strict
If you receive the above message and your Xbox 360 is behind a pfSense firewall then you can easily resolve the issue by changing how pfSense controls outbound NAT. Modify the outbound NAT settings using the directions below.
Modify Outbound NAT From Automatic To Manual On pfSense Firewall:
- Launch pfSense Management Interface: First connect to your pfSense firewall’s management interface which will look similar to the below example image.
- Firewall NAT: Now select Firewall in the top navigation menu and then select NAT from the drop down to open the pfSense Firewall NAT management interface as shown in the example image below.
- Firewall Outbound NAT: From the Firewall NAT configuration page click the Outbound tab which is located next to “1:1″ and will open the pfSense Outbound NAT configuration page as shown below.
- Modify Outbound NAT Behavior: First move the radio button from “Automatic outbound NAT rule generation” to “Manual outbound NAT rule generation” as shown in the below example. Once the radio button has been changed click the Save button to record the changes. Keep in mind you will still need to apply the changes which we will do after making the second change below.
- Static Port: While still on the Outbound NAT configuration page click the edit button, which is a small button with an “e” on it, to the right of the WAN Interface entry added after changing the outbound NAT to Manual. The interface’s outbound NAT configuration page will look similar to the below where you need to put a check in the Static Port check box and then click the Save button.
- Apply pfSense NAT Changes: After clicking the Save button above you will be redirected to the primary outbound NAT configuration page which will now have a Apply Changes button located near the top as shown in the below image. Click the Apply Changes button to apply the outbound NAT configuration changes.
Once the outbound NAT changes have been applied your Xbox 360 should no longer display that the NAT policy is Strict though it may still display that the NAT policy is Moderate unless you have already made the port forwarding changes necessary for the NAT to be configured properly for the Xbox 360. If you haven’t completed the port forwarding then look for another article in the next couple of days that will explain configuring the proper port forwarding on a pfSense firewall for the Xbox 360 NAT Type to function properly.
|
|
|
|




Entries (RSS)
Alex,
Thanks for putting this together. Have you published your follow up yet regarding the port forwarding rules? I trying to get my pfsense firewall setup for the Xbox before my kids come home for Xmas. This started at Thanksgiving and I’ve struggled with various recommendations on the net that never quite work. Yours, with the pfsense menu screen shouts has been very helpful. I now need the setup for the port forwarding rules. Thanks
[Reply]
alex Reply:
December 5th, 2010 at 3:43 PM
Hello ike,
Thanks for the positive feedback. I haven’t written the article yet for pfSense but will try to get to it tonight. You may also try this article I had written for forwarding the correct ports for a Xbox 360 through a router running DD-WRT firmware. Regardless I will try to get this article written tonight and post a follow up once I do.
We can’t deny those kids Xbox on Christmas!! :)
Thanks.
alex
[Reply]