Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT vpn if connection to a specific host.

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 673 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      swansense
      last edited by

      I have a VPN Server configured on Pfsense so i can access my home when im out and it works perfect.

      The problem I have is i have a machine on my network that i have limited control over, this VNC machine only allows access to it on its local subnet so i am not able to access it via VPN. The problem is when im out and about i can access my environment over VPN but i can not access this unless i RDP to another machine or something.

      Is it possible to configure Pfsense to NAT the connection and use a local lan IP when NATing if i a connection from the VPN network is trying to access this machine.

      I want to be able to configure a Pfsense to Nat the connect to the machine so the VNC machine thinks the traffic is coming from my local network and not my VPN network. the only port i really needed NAT'd is vnc port 5900

      so here is what i am trying to achieve using info i found on other threads
      Vpn network 10.99.8.0/24 ---> Nat traffic to 192.168.0.0/24 ---> VNC Machines 192.168.0.85

      I have tired a few different things but not really sure where to start.

      Here was one attempt but it doesnt work. Im not sure in this case what type of NAT i should be using so any help will be appreciated.

      [img]https://i.imgur.com/sG6HJEs.png[/img]

      JKnottJ johnpozJ 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @swansense
        last edited by

        @swansense

        Perhaps you could try OpenVPN tap mode, which is essentially a bridge between the 2 sites.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @swansense
          last edited by johnpoz

          @swansense said in NAT vpn if connection to a specific host.:

          Is it possible to configure Pfsense to NAT the connection and use a local lan IP when NATing if i a connection from the VPN network is trying to access this machine.

          Yeah you can do that, just create a outbound nat on the interface this device is on, lan I would assume. With destination to that specific IP source of your vpn tunnel network, using the lan address as the address.

          This will make it look like to the device your coming from your pfsense lan IP vs the IP of the vpn client tunnel network IP.

          If need be I could setup an example with my vpn showing you pictures..

          edit: Here you go just did example anyway. So pfsense lan IP is 192.168.9.253, my tunnel network for vpn is 10.0.200/24 - so at first you can see my vpn client pinging host on my lan network 192.168.9.100 coming from 10.0.200.250..

          I then created the outbound nat on the lan interface. Now the pings come from pfsense IP vs the vpn client IP.

          example.jpg

          You could get specific with the destination, for example I could of used specific 192.168.9.100/32 as the destination vs the whole network..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          S 1 Reply Last reply Reply Quote 2
          • S
            swansense @johnpoz
            last edited by

            @johnpoz

            wow that was a lot easier than i expected.

            thanks so much I literally spent days trying to figure this out and it worked without any issues.

            Thanks again and happy holidays.

            johnpozJ 1 Reply Last reply Reply Quote 1
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @swansense
              last edited by

              @swansense said in NAT vpn if connection to a specific host.:

              Thanks again and happy holidays.

              No problem - and a happy holidays to you as well..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.