• Port forwarding multiple vms same application different domains

    2
    0 Votes
    2 Posts
    495 Views
    johnpozJ

    @bossey1 said in Port forwarding multiple vms same application different domains:

    Will HAproxy added make this harder or easier?

    Unless you have multiple IPs there where you have X, if you did I would of assumed .X and .Y and .Y etc. given vs all .X

    If you have the same public IP and you want to hit different private IPs based on the domain, really only way to do it is with HAproxy.

    If you only have 1 public IP being used, you have to do other ports to get forwarded to different lan side IPs. If not using a reverse proxy.

    But with HAproxy you can look at the fqdn trying to go to, and direct that to different backend devices.

  • NAT that does not seem to work

    1
    0 Votes
    1 Posts
    350 Views
    No one has replied
  • NAT Outbound not working between VLANs

    28
    0 Votes
    28 Posts
    4k Views
    I

    @johnpoz
    Ok,
    So after tons of testing I think I can say it's the GeoIP causing the issue,
    Not sure why, and it's not consistent 100% of the time,
    But when Floating rules are enabled (and the interfaces are selected in inbound and outbound) and GeoIP is enabled as Deny Inbound, the issue exist.
    I wasn't able to reproduce the issue when Floating Rules was disabled.

    Sometimes even if Floating Rules was enabled and GeoIp was enabled then it worked (for example when changing the Floating Rules from disable to enable while GeoIp was enabled, it worked sometimes and no issue existed.

    Only if i disabled all GeoIp, forced PfBlocker to reload all rules (under Update), Enabled GeoIp, forced reload again then the issue happened I think every time.

    It also seems like for me, while I live in Israel (which is part of Asia Alias), Europe GeoIp caused more for the issue to happen, even if only one country from that filter was selected.

    I know it's not 100% step by step on how to re-produce the bug but that's what I managed to gather so far, hope it's enough.

    3d34463f-dbd7-4149-a18d-fe9ffc806a63-image.png

  • NAT and SIP

    1
    0 Votes
    1 Posts
    486 Views
    No one has replied
  • how to allow access from wan subnet

    8
    0 Votes
    8 Posts
    2k Views
    johnpozJ

    @nogbadthebad said in how to allow access from wan subnet:

    Yup, he could add the static route on 192.168.1.17.

    Yeah if your going to have hosts on your transit you would need to do host routing.. Its a hack, not a true setup anyone should want. When its simple enough to set it up correctly.

    To be honest you would almost never actually want/need a downstream router, your going the wrong direction that way to be honest. Just replace your edge with pfsense, use your old wifi router as just an AP as the transition phase until you can get AP that allow vlan and switches that can as well if you want to setup a real network ;)

    Yes in a large enterprise network you would see routing done internally all the time vs just at the edge.. But in a small network or home or home with lab setup just doesn't really make sense other than a learning experience. And if your wanting to learn, then do it correctly with a transit network.. Sure if you want to play with why it doesn't work when you have hosts on a transit and the asymmetrical traffic flow that will result - sure have at it.. But I would set it up correctly, then break it with putting hosts on your transit and see why the asymmetrical flow is not good when you have stateful firewalls also in play..

  • Returning IPSec traffic and NAT

    5
    0 Votes
    5 Posts
    623 Views
    S

    Hi @cswroe,

    Yes I created the Site-to-Site IPSec with NAT'ing using this link. The tunnel is UP together with Phase 2. I can also see traffic from Site A to Site B. When it enters the Site B and I do a packet capture, I can see the the NAT IP addresses.

    Thanks & Regards,
    Sam

  • New PFSense Configuration with Multiple Public Subnets

    1
    0 Votes
    1 Posts
    323 Views
    No one has replied
  • Wireguard and SIP

    1
    0 Votes
    1 Posts
    839 Views
    No one has replied
  • Alter outgoing port number is it possible?

    3
    0 Votes
    3 Posts
    498 Views
    R

    @viragomann thanks mate

  • Redirecting a subnet

    2
    0 Votes
    2 Posts
    470 Views
    V

    @pixel24 said in Redirecting a subnet:

    For the installation, I would like to access the new virtual network from the LAN

    You have two different LANs. Guess you mean this one 192.168.24.0/24.

    Is there a way to set up a redirection on the 'old' pfSense so that all calls for 192.168.83.0/24 from the network 192.168.24.0/24 are routed to the WAN IP of the 'new' pfSense (192.168.24.20)?

    Really not clear, why you want to do that. But yes, that's doable with a simple port forwarding rule, presupposed the old pfSense is the default gateway in the LAN.
    However, since both source and redirect target are within the same subnet, you need to masquerade the source IP.

    For masquerading add a rule in Firewall > NAT > outbound. If the outbound NAT is in automatic mode, switch into hybrid mode and save this first.
    Then add a new rule:
    interface: LAN
    source: LAN net
    dest.: 192.168.24.20
    translation: interface address (or LAN CARP VIP if any)

    Port forwarding:
    interface: LAN
    source: any
    dest: 192.168.83.0/2
    redirect target: 192.168.24.20

  • Help with Meraki MX64 client

    1
    0 Votes
    1 Posts
    356 Views
    No one has replied
  • Do I need to adjust NAT

    5
    0 Votes
    5 Posts
    648 Views
    N

    @viragomann

    Thank you! This helped me

  • NAT usinf l2tp on wan

    1
    0 Votes
    1 Posts
    299 Views
    No one has replied
  • 1 static pubblic ip address to 1 lan IP NAT (www.myip.com show wan ip!)

    9
    0 Votes
    9 Posts
    777 Views
    V

    @vitozzo
    It's quite simple. Post you 1:1 rule please.

    For troubleshooting use Diagnostic > Packet Capture.
    Sniff the traffic on WAN. Check out the IPs of www.myip.com and enter them in the Host box (multiple separated by "|").
    Start the capture and try to access www.myip.com from the internal device.
    You should see the packets going out with the source IP you stated at external in the 1:1 NAT rule.

  • How to NAT through a OpenVPN connection to my LAN

    12
    0 Votes
    12 Posts
    1k Views
    V

    @boeingpilot
    Also consider the option to set up a second OpenVPN connection. I'm thinking to run the server on the VPS, since it has a static IP.
    However, the rule setup I mentioned above has to be exactly the same.

    I was assuming, you need incoming connections only on the SMTP server. If you also need outbound using the VPS IP, you have to configure a CSO for the VPS client on the home pfSense, when using only one (multi purpose) server to let OpenVPN know the proper route. And you will have to policy route the servers outbound connections to the remote site.
    Additionally on the VPS you would need an outbound NAT rule for the SMTP server.

  • Need to perform NAT to a server cluster...

    4
    0 Votes
    4 Posts
    491 Views
    johnpozJ

    @narrington haproxy could do this for you..

    here is a google result that looks to be current version of pfsense and use of haproxy as load balancer

    https://getlabsdone.com/how-to-configure-pfsense-load-balancer-using-haproxy/

  • LAN Websites cannot be accessed

    23
    0 Votes
    23 Posts
    4k Views
    I

    @johnpoz yeah don’t worry I know they’re not the same but I’ve even tried to route through internally through PFSENSE by the host overrides and still nothing I am baffled

  • NAT Reflection and VLANs

    1
    0 Votes
    1 Posts
    378 Views
    No one has replied
  • Netduma Router behind Netgate Sg-2100 - gaming only

    3
    0 Votes
    3 Posts
    621 Views
    N

    @stephenw10 Figured out the issue! NAT 1:1 is indeed correct but i forgot to put the firewall rules in need inbound from WAN!

  • Multiple Devices behind NAT communicating

    4
    0 Votes
    4 Posts
    601 Views
    G

    Hi johnpos,
    I completed the NAT Reflection setup.
    It works as advertised both on Port Forward and 1:1 NATs
    Perfect result.
    Thanks

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.