Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access public IPv4s from LAN

    Scheduled Pinned Locked Moved NAT
    11 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      HrustakV
      last edited by

      Hi,

      I have a public /27 IPv4 subnet from my datacenter.

      I've assigned 89.x.x.222 IP to WAN, that's working properly. If I use DHCP on my servers behind the pfSense, the internet connection is working fine. But if I try to assign 89.x.x.196 from my subnet, it's not working.

      How can I access public subnet behind the FW?

      Thanks,
      H

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @HrustakV
        last edited by

        @hrustakv One can't use the same IP subnet on two interfaces. If you want to use public IPs on LAN you need the data center to give you an IP or a small routing subnet for your WAN. Then they route your /27 to an IP on the WAN, and pfSense will know to send those along to LAN.

        Otherwise you can use 1:1 NAT to map public IPs to private.

        Note if you have two routers you can use CARP for the WAN IP, to which they route your subnet.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        H 1 Reply Last reply Reply Quote 0
        • H
          HrustakV @SteveITS
          last edited by

          @SteveITS Thank you for answer.

          So, can I assign more IP addresses to the server using NAT? I want to use virtual servers on it with public IP binded (no local IPs using port forwarding). Is it possible?

          Otherwise, we will request for another IP.

          Thanks

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @HrustakV
            last edited by

            @hrustakv 1:1 NAT is using private IPs on LAN.

            If you want public IPs on LAN you need at least one (usually public) IP on WAN to which the data center will route them.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            H 1 Reply Last reply Reply Quote 0
            • H
              HrustakV @SteveITS
              last edited by

              @steveits Soo, I have to request an IP from another gateway? ๐Ÿ˜…

              S DerelictD 2 Replies Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @HrustakV
                last edited by

                @hrustakv Normally one can't use the same subnet on both sides of a router, or the router won't know where to route the traffic. The exception is a bridge if you want to go down that road. Otherwise what I'm talking about is here:
                https://docs.netgate.com/pfsense/en/latest/recipes/route-public-ip-addresses.html

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate @HrustakV
                  last edited by

                  @hrustakv Another document is here:

                  https://docs.netgate.com/pfsense/en/latest/firewall/additional-ip-addresses.html

                  You have: Single IP Subnet on WAN

                  You want: Small WAN IP Subnet with Larger LAN IP Subnet

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  H 1 Reply Last reply Reply Quote 0
                  • H
                    HrustakV @Derelict
                    last edited by

                    @derelict Hmm, and what if I use "Transparent bridge"?

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @HrustakV
                      last edited by

                      @hrustakv Up to you. I would get the service provisioned like I need it (routed subnet) if it was me.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      H 1 Reply Last reply Reply Quote 0
                      • H
                        HrustakV @Derelict
                        last edited by

                        @derelict So, I got info from my ISP, that they cannot assign me extra IPv4 from another gateway. If I assign IP to WAN, I can't use the subnet from LAN. If I assign IP to LAN, I don't have access to the internet. Is there any other way exclude port forwarding? Thanks.

                        H 1 Reply Last reply Reply Quote 0
                        • H
                          HrustakV @HrustakV
                          last edited by

                          @hrustakv I fixed the problem. I didn't have a bridge built over the WAN, only on LAN ports. :)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.