Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense changes subnet in the nat rules!!

    Scheduled Pinned Locked Moved General pfSense Questions
    22 Posts 3 Posters 1.9k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      If it's actually set to a /31 subnet it will show as that there:

      Screenshot from 2021-09-28 14-15-02.png

      Are you sure this is not your browser auto-fill setting some fields when you edit the rule?

      G 1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator @Gianluca 0
        last edited by

        @gianluca-0 said in PfSense changes subnet in the nat rules!!:

        try to see inside the rules in network

        Those are the wan rules.. Here our the nat rules

        natrules.jpg

        Yes this is a clean install of 2.5.2.. Sorry don't have a 5 year old test setup that I have kept updating over the years ;) heheh

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 2
        • G Offline
          Gianluca 0 @stephenw10
          last edited by

          @stephenw10 yes :) I'm sure..I understand what you're meaning. And autofill can not change from single host to network address and also change subnet to /31 (I think).

          G 1 Reply Last reply Reply Quote 0
          • G Offline
            Gianluca 0 @Gianluca 0
            last edited by

            anyway, I need some time to build a new Pfsense virtual machine and restore my configuration, so see what happened. Pfsense is not owned by us, we have a manager user but we cannot log in with ssh for example.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              There is something slightly odd there in 2.5.2/21.05.1. If you set the destination as network the list of subnet sizes includes /32 and also /31 twice!

              nat-rule-subnet.jpg

              However selecting them doesn't seen to cause a problem. And it's fixed in 2.6/21.09.

              Steve

              G johnpozJ 2 Replies Last reply Reply Quote 0
              • G Offline
                Gianluca 0 @stephenw10
                last edited by

                @stephenw10 but that Nat rules are single hosts, so / 32 is implied.

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Exactly. If you set /32 there it just goes back to single host. It should not appear in that list as a 'network' but selecting it does no harm.

                  Steve

                  1 Reply Last reply Reply Quote 1
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator @stephenw10
                    last edited by johnpoz

                    @stephenw10 said in PfSense changes subnet in the nat rules!!:

                    If you set the destination as network the list of subnet sizes includes /32 and also /31 twice!

                    Where are you seeing this? Looking on nat and firewalls - I do not see that

                    natfirewall.jpg

                    Oh I see it on 21.05.1 but not my test 2.5.2 box..

                    But only in the nat, not firewall rules..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      Yeah, I was testing in 21.05.1. I assume it would affect both. Hmm.

                      Either way it's fixed in 21.09 so...

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator @stephenw10
                        last edited by

                        @stephenw10 said in PfSense changes subnet in the nat rules!!:

                        Either way it's fixed in 21.09 so...

                        Which should be released any day ;) Since only a couple of days left in September (Month 9) hehehe..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.