Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1:1 NAT and Multiple Public IPs

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 3 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cdcarter
      last edited by

      Hello, Tomorrow I am going into my colo datacenter to install a pfSense firewall box.  I want to setup the the firewall to use 1:1 NAT on four servers.  I have 16 public IPs so that shouldn't be a problem.  I have never used pfSense before, so, the question is, can I do this easily through the web interface.  Should I just be able to alias more IPs to the public facing interface and then be able to 1:1 NAT them.  I was reading these forums and it looks like I may have to do the alias by hand with ifconfig.  I am an experianced *NIX user, so I can do that, but it would be nice if I could easily configure this via the web interface.  Do you have any good tips to help me get through this quickly, perhaps a walkthrough.  We want minimal downtime.  Thanks!

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        • Add virtual IPs for all your additional IPs (I suggest using CARP, this way you can add another machine for failover later easily)
        • Add 1:1 NATs between the virtual IPs and your internal IPs
        • Add firewallrules to allow traffic (destination is your internal IP as nat is applied first and firewallrules are matched after natting)
        1 Reply Last reply Reply Quote 0
        • M
          MrPK
          last edited by

          I had same problem, to map multiple WAN IP's to internal LAN/DMZ IPs. Example: 212.xx.xx.xx => 10.xx.xx.xx

          First I make Virtual IPs for every of my external IP (212.xx.xx.xx.) but it was not possible to use NAT 1:1 settings!
          You have to use "NAT Port Forward" insted. In the "External address" drop down you will see all your Virtual IPs and you can easy map them to your internal IPs and choose desired ports/ranges.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.