Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Outbound NAT

    Scheduled Pinned Locked Moved NAT
    8 Posts 3 Posters 3.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kapara
      last edited by

      Having problems setting up Outbound NAT for my Exchange server.  I have setup an inbound NAT:

      WAN  TCP  25 (SMTP)  172.20.30.189 (ext.: 206.13.X.130)  25 (SMTP)  SMTP to MAILSERVER Inbound

      The Outbound NAT Seems confusing.  I need to perform an outbound NAT from the same Internal IP to the Same external IP for email.

      InterfaceSource Source Port Destination Destination Port NAT Address NAT Port Static Port Description

      Having problems setting up Outbound NAT for my Exchange server.  I have setup an inbound NAT:

      WAN  TCP  25 (SMTP)  172.20.30.189 (ext.: 206.13.X.130)  25 (SMTP)  SMTP to MAILSERVER Inbound

      The Outbound NAT Seems confusing.  I need to perform an outbound NAT from the same Internal IP to the Same external IP for email.

      Interface - LAN

      Source  - 172.20.10.0/24

      Source Port *

      Destination *

      Destination Port *

      NAT Address - 206.13.x.130

      NAT Port *

      Static Port YES(25)

      Description  - Outbound for Exchange

      How would I set this rule up properly?

      Skype ID:  Marinhd

      1 Reply Last reply Reply Quote 0
      • H
        hoba
        last edited by

        Change LAN to WAN in your outbound nat rule and make sure that rule is on top of the default lan to wan outbound rule. Then it should work.

        1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash
          last edited by

          Also:

          1. That should be 172.20.10.189/32 ext 206.13.x.130
          2. You shouldn't need static ports for your mail server.
          1 Reply Last reply Reply Quote 0
          • K
            kapara
            last edited by

            Change LAN to WAN and keep the same subnet?  I do not have to specify the specific IP address on the inside?

            Skype ID:  Marinhd

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              @dotdash:

              Also:

              1. That should be 172.20.10.189/32 ext 206.13.x.130
              2. You shouldn't need static ports for your mail server.

              Yes, it should be a /32 for the IP. Overread that.

              The source is the specific IP. Btw, did you add a VIP for public IP already? I guess yes as the inbound is working ok, right?

              1 Reply Last reply Reply Quote 0
              • K
                kapara
                last edited by

                Yes I set up a VIP.

                Is that correct?

                Interface - WAN

                Source  - 172.20.10.189/32

                Source Port *

                Destination *

                Destination Port *

                NAT Address - 206.13.x.130

                NAT Port *

                Static Port No

                Description  - Outbound for Exchange

                Skype ID:  Marinhd

                1 Reply Last reply Reply Quote 0
                • K
                  kapara
                  last edited by

                  Also should I set Outbound NAT to Manual or leave it at Automatic?

                  Skype ID:  Marinhd

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by

                    The rule looks good. That will map any traffic from that host to that IP. If you only want smtp for example you could add that to the rule too. Make sure it's above the default lan to wan rule in the list. You need manual outbound nat to be turned on or it won't use your manually entered rules.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.