Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT with CARP

    Scheduled Pinned Locked Moved NAT
    7 Posts 2 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      geeko71
      last edited by

      Hi

      my config now:
                                                                                                                         |
                                                                                                                         | DMZ
                                                                                                               _____ 0
                                         NAT               192.168.250.0/24                       |         |                        172.16.52.0/21
      www–--------------------|Cisco3620|---------------------o-------------------C-----|fw1|----------------------------o---------
                        fix pub IP              .250                           |           .2           |                .55.248                       |
                                                                                    |                         |____                                           |
                                                                                    |                                  |                                         |
                                                                                    L--------------------------|fw2|--------------------------
                                                                                                                  .3        .55.249
                                                                                          Virtual IP(CARP)  .1        .55.250

      No, i'm not a painter :-)

      I just would like to switch the NAT service from the Cisco Router to the PF's, let the Cisco run as ADSL Bridge and let the PF's do PPPoE, that i can map some Ports in the DMZ.

      Is there an chance to do that with just 1 public IP ??....  i see no way, because FW1, 2 and the VIP's should be public in this case.

      Is there another chance to map some ports in the DMZ?

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        I have to admit that I don't completely understand your ASCII Artwork but dDepending on how your public IPs are set up you can do this with simple routing. Let the pfSense do the PPPoE Dialin with the cisco in bridge mode. then give your pfSense DMZ Interface one of your public IPs and the other public IPs to your DMZ Hosts with the pfSense public IP as gateway (this will only work if the WAN IP you get assigned is different from your other public subnet).

        1 Reply Last reply Reply Quote 0
        • G
          geeko71
          last edited by

          Hi HOBA

          that's the problem, i only have 1 Public IP Address, and 2 PF's as CARP cluster.
          or can i set my one IP as Virtual IP (WAN-CARP) ?

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            I'm starting to understand what you are trying to do. CARP won't work with PPPoE connections so it's not possible.

            1 Reply Last reply Reply Quote 0
            • G
              geeko71
              last edited by

              OK, then this plan will not work…...

              Then i leave NAT and PPPoE on the Cisco....

              can i use "double NAT". On the Cisco and on the PF's ?

              Then i can map ports trough 2 NAT Routers

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by

                Yeah, the easiest thing probably is to set the CARP VIP of your pfSense cluster as DMZ in the cisco and just double NAT the connections. Then you can control everything at the pfSense.

                1 Reply Last reply Reply Quote 0
                • G
                  geeko71
                  last edited by

                  Great !! THX 4 help

                  will continue on the german forum ;-)

                  cheers

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.