Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Non NAT setup

    NAT
    5
    11
    5.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      m1s1u
      last edited by

      I can see at least 2 solutions:

      • transparent firewall - pdf in pfSense tutorials http://www.pfsense.com/index.php?id=36
      • 1:1 nat - few topics on the forum
      1 Reply Last reply Reply Quote 0
      • B
        bnewbie
        last edited by

        Thanks for that, I'll give the transparent firewall a go and if not I'll try 1:1 NAT.

        Cheers,

        B.

        1 Reply Last reply Reply Quote 0
        • L
          lsf
          last edited by

          Add a DMZ interface, add your public iprange to this.
          Use lan interface as management interface only.

          Or enable advanced outbound nat and just remove the nat rule there.
          Then add filter rules as needed. As lanip set the public ip-range.

          -lsf

          1 Reply Last reply Reply Quote 0
          • B
            bnewbie
            last edited by

            @lsf:

            Add a DMZ interface, add your public iprange to this.
            Use lan interface as management interface only.

            I thought the DMZ is the area of the LAN where you trust things - so for machines you control rather than other users on the network? So no firewall rules will apply to these machines?

            Anyway no problem I'll try what suggested tomorrow and get back to you with my results.

            Cheers,

            B.

            1 Reply Last reply Reply Quote 0
            • L
              lsf
              last edited by

              DMZ/OPT it all depends on what you call it. Normally a DMZ is where you allow connections for the outside (like web/mail-servers etc).
              In general this is no different then any other zone. The normal firewall setup is to have a lan zone where no connections can be init. from the outside, but in your dmz you allow connections to be init. from the outside.
              Basically LAN is the safe haven, the DMZ is a semi strict zone.

              If you want both a DMZ and LAN with public ip's you can do that too, just remeber to remove the NAT rule.

              -lsf

              1 Reply Last reply Reply Quote 0
              • B
                bnewbie
                last edited by

                Thanks for the explanation that clears it up in my mind. It just seems every tutorial I read uses slightly different terms to mean the same thing so it's somewhat confusing for a newbie like me.

                Cheers for your help,

                B.

                1 Reply Last reply Reply Quote 0
                • H
                  hoba
                  last edited by

                  Please bump the green button if your topic is solved  ;D

                  1 Reply Last reply Reply Quote 0
                  • B
                    bnewbie
                    last edited by

                    @hoba:

                    Please bump the green button if your topic is solved  ;D

                    Sorry, haven't had a chance to try this out yet - too many other work related stuff. I'll let you guys know if it all works nicely.

                    Cheers,

                    Lawrence

                    1 Reply Last reply Reply Quote 0
                    • B
                      billm
                      last edited by

                      Everyone seems to have missed the, use advanced outbound nat and delete the auto-generated rules option.  If you truly don't want to NAT, that's how you do it.  You will of course need to route the traffic then…but I assume you knew that and can figure that part out.

                      --Bill

                      pfSense core developer
                      blog - http://www.ucsecurity.com/
                      twitter - billmarquette

                      1 Reply Last reply Reply Quote 0
                      • L
                        lsf
                        last edited by

                        I beleive that was explained here : http://forum.pfsense.org/index.php?topic=725.msg4419#msg4419

                        -lsf

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.