Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Routing - LAN w. Public IPs to WAN

    TNSR
    3
    9
    798
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      talwell
      last edited by

      I have a unique scenario. We have (2) public IP blocks from our ISP. The first block is routed and acts as the default gateway for both blocks. We use the public IPs on the LAN that route to the default gateway from the other block.

      I have tried a few things and cannot get the public IPs to route from LAN to WAN. What would a configuration like this look like?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @talwell
        last edited by

        @talwell

        https://docs.netgate.com/pfsense/en/latest/recipes/route-public-ip-addresses.html

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        T 1 Reply Last reply Reply Quote 0
        • T
          talwell @johnpoz
          last edited by

          @johnpoz thank you but I want to do in TNSR, not Pfsense.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @talwell
            last edited by

            @talwell oh my bad - sorry... But would be the same sort of thing, just don't nat the traffic on the public IP range you on an interface behind tnsr

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            T 1 Reply Last reply Reply Quote 0
            • T
              talwell @johnpoz
              last edited by talwell

              @johnpoz I am able to ping as far as the inside of the WAN interface from the LAN public IP block. From there it doesn't hit default gateway or internet. I can however get out through default gateway from WAN or from NAT'd LAN interfaces.

              1 Reply Last reply Reply Quote 0
              • T
                talwell
                last edited by

                Any help??

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  @talwell Nothing special should be needed. Just assign the interface subnet to the outside interface and the routed subnet to an inside interface. Set the default gateway to the ISP gateway on the interface subnet.

                  Sounds like simple routing.

                  This all assumes that is how the ISP circuit is actually provisioned.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  T 1 Reply Last reply Reply Quote 0
                  • T
                    talwell @Derelict
                    last edited by talwell

                    @derelict I would have thought so as well but it doesnt work. I can only ping as far as the WAN (ISP subnet with default gateway) from the public subnet that is routed. I am not understanding why I cannot even hit the default gateway (0.0.0.0/0) IP address if I am able to ping the interface attached to it. Subnets behind NAT work fine as does the WAN - just not the routed network LAN interface.

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @talwell
                      last edited by

                      @talwell Perhaps the subnet is not routed properly by the ISP?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.