• NAT Outbound Pool in a High Availability enviroment?

    5
    0 Votes
    5 Posts
    543 Views
    D
    OK, that makes sense. Thanks for the quick response.
  • Issues with virtual IP routing :-/

    2
    0 Votes
    2 Posts
    369 Views
    L
    Ohh looks like I resolved the issue by forcing all traffic through gateway :-)
  • Once again: no internet access for VLAN

    22
    0 Votes
    22 Posts
    12k Views
    johnpozJ
    Your right about the source being only opt1 good catch, I didn't catch that - sorry.
  • Virtual IP to Outgoing Address

    2
    0 Votes
    2 Posts
    411 Views
    V
    It's possible to use virtual IPs for forwarding, but it's not possible to assign 192.168.1.125 to the client LAN, since that IP is out of the server LANs network. However, you don't need to assign a virtual IP for what you intent if pfSense is the default gateway in the client LAN. If so, just add a NAT port forwarding rule to the client LAN for dest: 192.168.1.125:443 target: 195.78.228.226:443 and it will do the job.
  • Outgoing NAT'ing from a single IP

    12
    0 Votes
    12 Posts
    1k Views
    _neok_
    @_neok said in Outgoing NAT'ing from a single IP: @jimp thanks for reply. I was able to make it work. There are some tricks to make it work well. Now I have to go. Tomorrow I write how I made it work. Bye Gabriel I had a rule to allow me to navigate my entire LAN through another gateway. I had to make an IP alias of my LAN by taking out the local IP in question. Along with that I set the local IP to go out to the internet through the same gateway over which is the interface that has the VIP associated. That, in combination with the Hybrid Outbound NAT and that's it. I was able to fix it. Thanks for help Best regards Gabriel
  • need help in outbound traffic through vips from lan

    5
    0 Votes
    5 Posts
    557 Views
    DerelictD
    Never set Outbound NAT from source any. Set it to the inside networks that actually need NAT to happen. I would suggest you start by enabling automatic mode and trying again unless you can state why you need manual outbound NAT.
  • 0 Votes
    6 Posts
    1k Views
    M
    @johnpoz My configuration in: System / Advanced / Firewall & NAT / Network Address Translation / NAT Reflection mode for port forwards is set to "NAT + Proxy" and when I set to "Pure NAT", I can list the ftp content from LAN So, it seems a solution, as it works. But as I have set Squid Proxy, perhaps it's not a good idea to set "Pure NAT"? Otherwise, can I create a rule which simulate the "Pure NAT" setup with "NAT + Proxy"?
  • Moving from VYOS to PSFSENSE

    Locked
    5
    0 Votes
    5 Posts
    1k Views
    NogBadTheBadN
    Never done it myself but try:- https://www.netgate.com/docs/pfsense/book/nat/1-1-nat.html#example-ip-address-range-1-1-configuration
  • Web Server & SSH port forward issues

    port forward ssh dual lan
    7
    0 Votes
    7 Posts
    2k Views
    W
    @kom The first link I glanced over before but I can now access the web server both on the WAN and LAN. I'm even able to ssh to it from LAN to OPT1. I don't remember if it was one of the videos you linked or some random third video but I didn't understand that request get sent out on a random port. So those source ports would have never worked. Sorry for not understanding that sooner. Thank you for the references and your time.
  • Redirect to Wan IP

    1
    0 Votes
    1 Posts
    263 Views
    No one has replied
  • Forward Traffic from Virtual IP to target behind WAN

    7
    0 Votes
    7 Posts
    892 Views
    A
    @kom said in Forward Traffic from Virtual IP to target behind WAN: OK. Now what about the captures? That's the only way to really see what's happening. I went the easy route and ditched my previous attempts. I just created Port Forwarding Rules for the required hosts. Not elegant, but works for me. Interface Protocol Source Address Source Ports Dest. Address Dest. Ports NAT IP NAT Ports LAN TCP/UDP * * 192.168.20.2 1 - 65535 192.168.1.2 1 - 65535 LAN TCP/UDP * * 192.168.20.1 1 - 65535 192.168.1.1 1 - 65535 Sorry for the delay (blame it on the holidays )
  • Adding large number of NAT policy without disturbing the existing NAT conf.

    20
    0 Votes
    20 Posts
    2k Views
    T
    @johnpoz If we create 1:1 NAT then we have to create IPalias(VIP) for each public IP ryt?
  • How to configure NAT from Shell Command?

    1
    0 Votes
    1 Posts
    319 Views
    No one has replied
  • When OpenVPN is up WAN Outbound stops

    3
    0 Votes
    3 Posts
    481 Views
    C
    @derelict Oh man... I knew it was something simple. I had done this once before and completely forgot about that "Don't Pull Routes" option. Thank you so much!
  • SSH Port Forwarding from custom ports to port 22 does not work!

    3
    0 Votes
    3 Posts
    981 Views
    S
    Thanks for your response. I have double check all the config and the problem was that this network do not have full internet connectivity. Only ICMP and DNS works. The solution turned out to be to disable hardware checksum offloads. Now all works fine. We can close this case.
  • NAT Reflection, Which one to use?

    7
    0 Votes
    7 Posts
    900 Views
    V
    Okay thanks for that. I think I have the split DNS working okay and will find out tomorrow when I turn the NAT reflection off.
  • Virtual IPs Port Forwarding

    2
    0 Votes
    2 Posts
    588 Views
    DerelictD
    Why do you have a VIP on WAN in the same subnet as LAN?
  • Outbound NAT Issue

    5
    0 Votes
    5 Posts
    708 Views
    DerelictD
    You should not need any floating rules. You do need rules on LAN that pass all of the traffic coming from the downstream router. It looks like you have that as all of RFC1918. That might or might not be a problem as you add VPN connections. I would move them from floating to the LAN interface tab. It's much more straightforward.
  • setting default port forwarding. possible?

    3
    0 Votes
    3 Posts
    397 Views
    johnpozJ
    that would be a 1:1 nat... And to be honest really never a good idea.. How many freaking ports could you ever need to see unsolicited traffic on? Normally this would only be done when the customer is behind your firewall and they run their own firewall, etc. If this box is under your control - just forward the ports you need to it.
  • Outbound NAT problem on OPT1 using OpenVPN

    7
    0 Votes
    7 Posts
    934 Views
    L
    Sorry, but I've been studying documentation for a couple of days till now where Im really stuck :( Outbound rules: [image: 1545934796498-zrzut-ekranu-2018-12-27-o-19.17.03-resized.png] Port forwarding: [image: 1545934821311-zrzut-ekranu-2018-12-27-o-19.17.37-resized.png] and connected Firewall rule: [image: 1545934844786-zrzut-ekranu-2018-12-27-o-19.18.39-resized.png] Firewall passes packets: [image: 1545934896120-zrzut-ekranu-2018-12-27-o-18.26.39-resized.png] but blocks connections back: [image: 1545934948048-zrzut-ekranu-2018-12-27-o-18.17.22-resized.png] and I dont know the reason because Im not filtering LAN to OPT1 connections: [image: 1545935069532-zrzut-ekranu-2018-12-27-o-19.23.38-resized.png]
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.