Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access public IPv4s from LAN

    Scheduled Pinned Locked Moved NAT
    11 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @HrustakV
      last edited by

      @hrustakv One can't use the same IP subnet on two interfaces. If you want to use public IPs on LAN you need the data center to give you an IP or a small routing subnet for your WAN. Then they route your /27 to an IP on the WAN, and pfSense will know to send those along to LAN.

      Otherwise you can use 1:1 NAT to map public IPs to private.

      Note if you have two routers you can use CARP for the WAN IP, to which they route your subnet.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote ๐Ÿ‘ helpful posts!

      H 1 Reply Last reply Reply Quote 0
      • H
        HrustakV @SteveITS
        last edited by

        @SteveITS Thank you for answer.

        So, can I assign more IP addresses to the server using NAT? I want to use virtual servers on it with public IP binded (no local IPs using port forwarding). Is it possible?

        Otherwise, we will request for another IP.

        Thanks

        S 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @HrustakV
          last edited by

          @hrustakv 1:1 NAT is using private IPs on LAN.

          If you want public IPs on LAN you need at least one (usually public) IP on WAN to which the data center will route them.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          H 1 Reply Last reply Reply Quote 0
          • H
            HrustakV @SteveITS
            last edited by

            @steveits Soo, I have to request an IP from another gateway? ๐Ÿ˜…

            S DerelictD 2 Replies Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @HrustakV
              last edited by

              @hrustakv Normally one can't use the same subnet on both sides of a router, or the router won't know where to route the traffic. The exception is a bridge if you want to go down that road. Otherwise what I'm talking about is here:
              https://docs.netgate.com/pfsense/en/latest/recipes/route-public-ip-addresses.html

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote ๐Ÿ‘ helpful posts!

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate @HrustakV
                last edited by

                @hrustakv Another document is here:

                https://docs.netgate.com/pfsense/en/latest/firewall/additional-ip-addresses.html

                You have: Single IP Subnet on WAN

                You want: Small WAN IP Subnet with Larger LAN IP Subnet

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                H 1 Reply Last reply Reply Quote 0
                • H
                  HrustakV @Derelict
                  last edited by

                  @derelict Hmm, and what if I use "Transparent bridge"?

                  DerelictD 1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate @HrustakV
                    last edited by

                    @hrustakv Up to you. I would get the service provisioned like I need it (routed subnet) if it was me.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    H 1 Reply Last reply Reply Quote 0
                    • H
                      HrustakV @Derelict
                      last edited by

                      @derelict So, I got info from my ISP, that they cannot assign me extra IPv4 from another gateway. If I assign IP to WAN, I can't use the subnet from LAN. If I assign IP to LAN, I don't have access to the internet. Is there any other way exclude port forwarding? Thanks.

                      H 1 Reply Last reply Reply Quote 0
                      • H
                        HrustakV @HrustakV
                        last edited by

                        @hrustakv I fixed the problem. I didn't have a bridge built over the WAN, only on LAN ports. :)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.