• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Outbound NAT

NAT
2
7
617
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    MattL88
    last edited by Jul 26, 2022, 3:11 PM

    Help me out here I'm going around in circles.

    I have an internet connection DHCP wan address all working ok.

    I have a L2TP service that gives me a IP pool ie. 1.2.3.72/29

    I can set the port forwards up inbound to allow services on them IP's to work but I want a number of devices on the network when they are outbound to get one of the IP's in the pool that I allocate as such.

    i.e. voice 74, server1 75 and server2 76.

    I have the virtual IP's setup, I have looked at 1:1 NAT but no joy, and outbound I have it set on hybrid but have tried auto, hybrid and manual and no joy. The 3 things I want to have an IP from that pool all sit on the same /24 network.

    What am I missing here.

    S 1 Reply Last reply Jul 26, 2022, 3:50 PM Reply Quote 0
    • S
      SteveITS Galactic Empire @MattL88
      last edited by Jul 26, 2022, 3:50 PM

      @mattl88 Can you post what you have? In essence, for hybrid, add one mapping:
      interface: WAN
      source: server_private_ip
      NAT Address: .74

      And that's about it. Any open states may need to be deleted but new connections should go out on the .74 IP.

      No rules are needed if using 1:1 NAT as that is automatic.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      M 1 Reply Last reply Jul 26, 2022, 3:57 PM Reply Quote 0
      • M
        MattL88 @SteveITS
        last edited by Jul 26, 2022, 3:57 PM

        @steveits login-to-view

        That is my current setup, the sources are just the IP's of the 3 servers for example, the top one is a test PC.

        The interface is the L2TP tunnel.

        S 1 Reply Last reply Jul 26, 2022, 4:49 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @MattL88
          last edited by Jul 26, 2022, 4:49 PM

          @mattl88 And if you pull up a (new) web browser on the Windows DC and go to http://checkip.dyndns.com/ you get the WAN IP not .76?

          How are the .73-.76 IPs configured on pfSense? As virtual IPs?

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          M 1 Reply Last reply Jul 26, 2022, 5:34 PM Reply Quote 0
          • M
            MattL88 @SteveITS
            last edited by Jul 26, 2022, 5:34 PM

            @steveits It shows my WAN address. All are virtual IP's.

            Ok looking at this I might have done something stupid, my default gateway has been set to WAN address/automatic. If I change that to the L2TP it then gives me the right addresses.

            Do I need to force all traffic out the L2TP tunnel as the default gateway?

            Can I have different gateways for different devices?

            S 1 Reply Last reply Jul 26, 2022, 5:38 PM Reply Quote 0
            • S
              SteveITS Galactic Empire @MattL88
              last edited by Jul 26, 2022, 5:38 PM

              @mattl88 I don't know if I've set up outbound NAT and multiple WANs. Huh.

              pfSense has policy routing which I think is what you're looking for.
              https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              M 1 Reply Last reply Jul 26, 2022, 5:55 PM Reply Quote 0
              • M
                MattL88 @SteveITS
                last edited by Jul 26, 2022, 5:55 PM

                @steveits That might just do it, thanks, will have a play with that, never noticed the option below regarding gateway on a rule. Just done some testing and looks good but need to do some more. Thanks for that.

                1 Reply Last reply Reply Quote 0
                6 out of 7
                • First post
                  6/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.