• how to find out through what the "NAT + PROXY" function does

    2
    0 Votes
    2 Posts
    408 Views
    S
    @msibyte https://docs.netgate.com/pfsense/en/latest/nat/reflection.html "NAT reflection refers to the ability to access external services from the internal network using the external (usually public) IP address, the same as if the client were on the Internet." NAT + Proxy is one method to do this. It has nothing to do with access from the Internet, that is just plain old NAT.
  • I Can't get internet connection from other side of BGP route.

    1
    0 Votes
    1 Posts
    320 Views
    No one has replied
  • Access Server On LAN1 From LAN2 With VIP

    8
    0 Votes
    8 Posts
    703 Views
    johnpozJ
    @urbnsr And no real reason for a vip with a reverse proxy, just have it listen on the IP of pfsense on that vlan on port X, and backend is your destination be that the same port X or a different port, etc.
  • single WAN /27 ip block multiple PFSense routers

    11
    1
    0 Votes
    11 Posts
    1k Views
    J
    @johnpoz figured it out. It was as stupid thing I did to try to remember the public IPs I had given the virtual networks. I set them up as virtual IPs and labeled them Do Not Use thinking it would just be a place holder that would not matter unless I created a NAT policy with them. But, apparently it does matter. After I deleted those virtual IPs, all traffic came back and web access resumed. I'm an idiot. Thanks for your assistance!
  • dns redirection - local requests being redirected

    3
    3
    0 Votes
    3 Posts
    387 Views
    O
    Nevermind, I've worked out what's going on. That firewall rule is catching all dns traffic not just the redirected traffic. It had me confused for a while!
  • 0 Votes
    3 Posts
    396 Views
    S
    @viragomann Perfect, thank you!
  • NAT Reflection not working on Bridged network segment

    2
    0 Votes
    2 Posts
    452 Views
    S
    The answer is yes and no. No: If you only have 1 public IP address because your OpenVPN will be on the same Public IP as your assets such as a webserver. Yes: If you have 2 Public IPs and the assets you are trying to access are not on the same public IP as your OpenVPN server.
  • port forwarding problem

    11
    0 Votes
    11 Posts
    1k Views
    S
    @johnpoz Thanks for the answers.
  • Access servers behinf firewall by local clients

    3
    0 Votes
    3 Posts
    463 Views
    A
    Thanks Steve! Finally got the right option. Had to use NAT + Proxy.
  • NAT with translation

    3
    1
    0 Votes
    3 Posts
    444 Views
    W
    Hi, it is a typo on the graphic, i need to translate users IP 192.168.231.0/24 into 10.33.25.0/24 on the global architecture, i use a different gateway to route users. on the vlan created and used to connect pfSense WAN and Meraki, i was able to mention that i would use a different gateway in my interface i.e. Meraki (i use Unifi devices). Is there route back pointing to 172.30.10.4 on the customer network for the subnet you want use for translation? not for the moment
  • 0 Votes
    2 Posts
    243 Views
    GertjanG
    @dbmadmin This might be the issue : "cobine 2 wans". As I have a pfSense, a (one) WAN, default setup, using DHCP and a LAN, default setup, 192.168.1.1/24 - also all default with default DHCP server setup. I've also a access point, living on LAN (192.168.1.2/24 - gateway 192.168.1.1) and I have a Phone and Whatssapp. Nothing else it needed : the Whatssapp app can go 'out' and connect to needed servers. I have also an upstream ISP router, no setting changes needed.
  • NPt, Prefix Delegation from ISP and local prefixes

    2
    0 Votes
    2 Posts
    333 Views
    NightlySharkN
    Bump.
  • Cant hear anything on the VOIP phone

    8
    1
    0 Votes
    8 Posts
    858 Views
    S
    @gblenn I am very grateful for your assistance. I will take your suggestion and advise and see how I can turn this around. Thank you very much for your time
  • Inbound port forwarding via a single static public IP

    10
    0 Votes
    10 Posts
    861 Views
    E
    @steveits I found the problem. Though the screens said to not use redirection, that is what I actually needed to do. It was a simple fix, once I realized the screen instructions were at best misleading. It all works now. Here's what it looks like. [image: 1678285064257-fixed.png]
  • wireguard site to site port forwarding Nginx

    1
    5
    0 Votes
    1 Posts
    279 Views
    No one has replied
  • Outbound NAT to a specific URL

    5
    0 Votes
    5 Posts
    538 Views
    A
    @viragomann Just wanted to let you know I was able to get this done. I remember a long time ago a list of aliases would show up in some of the fields (since I am using the GUI). I modified the alias to be hosts and that worked when I added the alias as the destination in the Outbound NAT rule. Thank you for your input.
  • IPsec Mobile > IPsec Tunnel with Virtual IP

    2
    0 Votes
    2 Posts
    236 Views
    No one has replied
  • I suspect yet another port forwarding problem - please help

    6
    1
    0 Votes
    6 Posts
    781 Views
    johnpozJ
    @dharvey242 glad you got is sorted..
  • SNAT

    2
    0 Votes
    2 Posts
    301 Views
    V
    @munchie If you do SNAT on packets, which are going to a device, it sees only the NAT IP, nothing else. If you want to see the origin clients IP remove the SNAT rule and set pfSense as default gateway on the web server.
  • NAT not working when destination and redirecting port are different

    8
    1
    0 Votes
    8 Posts
    558 Views
    S
    @landomix no it should have an open state for the reply. Presumably the gateway on the server is the pfSense because it works on the other port. You could check states and/or a packet capture on LAN… Have you tried a different alt port? It shouldn’t care but…
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.