Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static route for avoid double NAT

    Scheduled Pinned Locked Moved Routing and Multi WAN
    30 Posts 2 Posters 2.6k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      viragomann @Antibiotic
      last edited by

      @Antibiotic
      09e2ff6e-66f4-4220-af2f-29c87723f6f0-grafik.png

      The red one.

      In the yellow you might want to change the source address accordingly.

      Also remember, that you have to change the source in the outbound NAT rule on the VPN interface to the new network.

      A 3 Replies Last reply Reply Quote 0
      • A Offline
        Antibiotic @viragomann
        last edited by Antibiotic

        @viragomann I would like to tell you a big thanks, now everything start working over VPN! What I have now Asus router in router mode, because want to use QOS , statistic and etc and eliminated double NAT. Thank you my friend))) Tried to make to work this static route a few times without success, now I'm happy)))

        pfSense plus 24.11 on Topton mini PC
        CPU: Intel N100
        NIC: Intel i-226v 4 pcs
        RAM : 16 GB DDR5
        Disk: 128 GB NVMe
        Brgds, Archi

        1 Reply Last reply Reply Quote 0
        • A Offline
          Antibiotic @viragomann
          last edited by

          @viragomann said in Static route for avoid double NAT:

          Also remember, that you have to change the source in the outbound NAT rule on the VPN interface to the new network.

          That was a point))))

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          1 Reply Last reply Reply Quote 0
          • A Offline
            Antibiotic @viragomann
            last edited by

            @viragomann But in this settings pfSesne firewall will logging this network 192.168.100.0/24 and pfblockerNG will see this network?

            pfSense plus 24.11 on Topton mini PC
            CPU: Intel N100
            NIC: Intel i-226v 4 pcs
            RAM : 16 GB DDR5
            Disk: 128 GB NVMe
            Brgds, Archi

            V 1 Reply Last reply Reply Quote 0
            • V Offline
              viragomann @Antibiotic
              last edited by

              @Antibiotic
              Yes, for pfSense. pfBlocker will not care about networks by default. Just ensure that the ASUS interface is selected in "Outbound Firewall Rules".

              A 2 Replies Last reply Reply Quote 0
              • A Offline
                Antibiotic @viragomann
                last edited by

                @viragomann Ok)))

                pfSense plus 24.11 on Topton mini PC
                CPU: Intel N100
                NIC: Intel i-226v 4 pcs
                RAM : 16 GB DDR5
                Disk: 128 GB NVMe
                Brgds, Archi

                1 Reply Last reply Reply Quote 0
                • A Offline
                  Antibiotic @viragomann
                  last edited by Antibiotic

                  @viragomann What I do not understand, for example on Asus router DCHP server switched off and me thought that devices connected to Asus router should have IP in range from DCHP of pfSesne router. Let's say 192.168.20.122 can you please explain this? or could be better to leave DCHP server on ASus router ON?

                  pfSense plus 24.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  V 1 Reply Last reply Reply Quote 0
                  • V Offline
                    viragomann @Antibiotic
                    last edited by

                    @Antibiotic
                    Pulling an IP from pfSense would only work, if the Asus router supports DHCP relaying. But I don't think, that it has this option.

                    DHCP requests don't pass a router otherwise.

                    If not, you will have to enable the DHCP server on the router.
                    Or you set it into AP mode (layer 2 bridge) if possible. In this case you would have to change the rules back to Asus subnet sources.

                    A 2 Replies Last reply Reply Quote 0
                    • A Offline
                      Antibiotic @viragomann
                      last edited by

                      @viragomann Ok)))

                      pfSense plus 24.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      1 Reply Last reply Reply Quote 0
                      • A Offline
                        Antibiotic @viragomann
                        last edited by

                        @viragomann I will get back DCHP server on Asus router , but do I need to make ON Advertise router's IP in addition to user-specified DNSScreenshot_11-11-2024_183350_192.168.20.2.jpeg "

                        pfSense plus 24.11 on Topton mini PC
                        CPU: Intel N100
                        NIC: Intel i-226v 4 pcs
                        RAM : 16 GB DDR5
                        Disk: 128 GB NVMe
                        Brgds, Archi

                        V 1 Reply Last reply Reply Quote 0
                        • V Offline
                          viragomann @Antibiotic
                          last edited by viragomann

                          @Antibiotic
                          No, this would set clients DNS to the routers IP.
                          As DNS server enter the IP of pfSense, presuming you're running DNS resolver or forwarder.

                          A 1 Reply Last reply Reply Quote 0
                          • A Offline
                            Antibiotic @viragomann
                            last edited by Antibiotic

                            @viragomann How better in this config connect router and pfSense ? pfSesne LAN to router WAN or LAN? or doesn't matter? Because me filling very small delays when browsing now! Do not understand the cause of this. Looks like delay in dns resolving

                            pfSense plus 24.11 on Topton mini PC
                            CPU: Intel N100
                            NIC: Intel i-226v 4 pcs
                            RAM : 16 GB DDR5
                            Disk: 128 GB NVMe
                            Brgds, Archi

                            V 1 Reply Last reply Reply Quote 0
                            • V Offline
                              viragomann @Antibiotic
                              last edited by

                              @Antibiotic
                              The wifi is possibly bridged to the LAN ports. So when connecting to the LAN, the wifi clients are in the same L2 with pfSense.
                              It this is the case you would be able to use the DHCP on pfSense.

                              However, I'm not expecting, that there is a measurable delay, when you connect to its WAN.

                              A 1 Reply Last reply Reply Quote 0
                              • A Offline
                                Antibiotic @viragomann
                                last edited by Antibiotic

                                @viragomann Hello again, everything is working fine. But sometimes have a delay in opening sites, like 1,2 sec delays. Looks like resolving delay. Could you please give a tip, what to check? Here are my settings:
                                Screenshot_12-11-2024_131743_192.168.20.1.jpeg
                                Screenshot_12-11-2024_131718_192.168.20.1.jpeg
                                Screenshot_12-11-2024_13209_192.168.20.1.jpeg
                                Screenshot_12-11-2024_132517_192.168.20.1.jpeg
                                Screenshot_12-11-2024_13254_192.168.20.1.jpeg
                                Screenshot_12-11-2024_132453_192.168.20.1.jpeg
                                Screenshot_12-11-2024_132425_192.168.20.1.jpeg
                                Screenshot_12-11-2024_132438_192.168.20.1.jpeg
                                Screenshot_12-11-2024_133042_192.168.20.1.jpeg
                                Screenshot_12-11-2024_132922_192.168.20.1.jpeg

                                Unbound " network interfaces " also checked all local interfaces as well and " outbound network interfaces " only localhost

                                pfSense plus 24.11 on Topton mini PC
                                CPU: Intel N100
                                NIC: Intel i-226v 4 pcs
                                RAM : 16 GB DDR5
                                Disk: 128 GB NVMe
                                Brgds, Archi

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.