Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT, Rules, and VPN

    Scheduled Pinned Locked Moved NAT
    8 Posts 4 Posters 466 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Amp911
      last edited by

      I'm using NAT to forward everything from my LAN to TrustZone. It works fine. I'd like to be able to use rules to forward several individual links (by IP) directly to my WAN interface without going through TrustZone. Please advise.

      Bob.DigB V 2 Replies Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @Amp911
        last edited by Bob.Dig

        Why do you use NAT in the first place, what is TrustZone.

        @Amp911 said in NAT, Rules, and VPN:

        Please advise.

        Start over with a fresh install.

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann @Amp911
          last edited by

          @Amp911 said in NAT, Rules, and VPN:

          . I'd like to be able to use rules to forward several individual links (by IP) directly to my WAN interface

          You can forward packets to an IP and a port, but not to an interface. Do you mean, to the WAN IP?

          And if what's the benefit? Is your WAN listening for services?

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            Amp911 @viragomann
            last edited by

            @viragomann My apologies, TrustZone is a VPN/Gateway. All the outbound traffic is routed/NAT'd out that way. Some web sites don't like when you hide your IP/Location. So I have rules setup for each of them, but everything gets routed to TrustZone. My LAN is a class-C private network.

            V 1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann @Amp911
              last edited by

              @Amp911
              So presumably the VPN is your default gateway.
              Then you need a policy routing rule to route the certain IPs to WAN.

              Put all the concerned destination IPs into an alias.
              Then add a rule to the top of the LAN rule set with the alias as destination, open the advanced options and at gateway select the WAN gateway.

              A 1 Reply Last reply Reply Quote 0
              • A Offline
                Amp911 @viragomann
                last edited by

                @viragomann It took a full power off, reboot. But all is well. I will try the alias as you suggest, that seems cleaner than 50 rules. Thank you!!

                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG Offline
                  Gertjan @Amp911
                  last edited by

                  @Amp911 said in NAT, Rules, and VPN:

                  It took a full power off

                  You mean : you used :

                  703bfb8d-cea8-4c10-8dfb-b105c76cac08-image.png

                  as taken off the power like that is very ( !) bad.

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    Amp911
                    last edited by

                    As in, Halt System. Then push the power button to turn back on.

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.