Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT Reflection Issue with Dual WAN Setup in pfSense 2.7.2

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 3 Posters 250 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      TonyArizin @viragomann
      last edited by

      @viragomann

      The LAN rule already has the source set to all and all ports going out are open.

      V 1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @TonyArizin
        last edited by

        @TonyArizin
        The destination has to be the local IP of the server, not the public one, since this is, what you want to access in fact.

        T 1 Reply Last reply Reply Quote 0
        • T Offline
          TonyArizin @viragomann
          last edited by

          @viragomann

          First of all, thank you for your answer.

          So, does that mean that in the LAN firewall rule, the source should be any and the destination should be the internal address of the web publishing server?

          In addition, there is already a LAN firewall rule with the source set to any and the destination set to any. Does that mean that I need to add what you mentioned in addition to this?

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            The default LAN to any rule should pass that traffic.

            What rule did you add exactly?

            T 1 Reply Last reply Reply Quote 0
            • T Offline
              TonyArizin @stephenw10
              last edited by

              @stephenw10

              protocol is ipv4*
              source is *(any)
              port is also *(any)
              destination *(any)
              I created a rule like this, but the only special thing is that I set the gateway to be a gateway group.

              V 1 Reply Last reply Reply Quote 0
              • V Offline
                viragomann @TonyArizin
                last edited by

                @TonyArizin
                Stating a gateway turns the rule into a policy-routing rule. Then all matching traffic is forced to the gateway.
                Hence this rule doesn't allow access to internal destinations.

                1 Reply Last reply Reply Quote 1
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Yup, that^ 😉

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    TonyArizin
                    last edited by

                    First of all, thank you for your answer.

                    Then, if I specify a gateway other than the default, do I need to create a LAN rule for it? Can you show me an example of a LAN rule that I need to create?

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      Yes if you are policy routing traffic from LAN via a specific gateway you need another rule above that to allow traffic to other local destinations that avoids policy routing.

                      So for example:
                      Screenshot from 2025-07-25 01-17-11.png

                      There I'm using an alias 'LOCAL' that contains all the subnets I need to bypass policy routing for.

                      T 1 Reply Last reply Reply Quote 0
                      • T Offline
                        TonyArizin @stephenw10
                        last edited by

                        @stephenw10

                        I understand.

                        I think you set the source to LAN subnets and the destination to 'LOCAL', but can you actually use the internal IP of the web publishing servers I mentioned as an alias for 'LOCAL'?

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Yes as long as it matches the traffic against a rule that's above the policy routing rule that will work.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.