Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple IPs from one WAN

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Perry
      last edited by

      My guess is transparent firewall / filtered bridge
      http://doc.m0n0.ch/handbook/examples-filtered-bridge.html
      http://pfsense.trendchiller.com/transparent_firewall.pdf

      /Perry
      doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        Or if not bridging, you might want a /30 on your WAN, and have your ISP route that public IP block to your WAN IP, then disable NAT on pfSense.

        Either/or will work fine.

        1 Reply Last reply Reply Quote 0
        • X
          xbr
          last edited by

          Not working.

          Anyway, can i do this?:
          modem->pfsense(router)->switch->3servers+20workstations

          One ip for all workstations.
          And three ips for 3 servers. And those servers in the same lan as workstations. I mean same lan subnet.
          For example: wan ip: 77.xxx.xxx.74 holds 192.168.1.1-192.168.1.20 workstations. And  213.xxx.xxx.21 - 213.xxx.xxx.23 ips holds 192.168.1.21 - 192.168.1.23 servers. Is it possible? (one wan one lan interface in pfsense)

          (it's difficult to convey what i want in english)

          1 Reply Last reply Reply Quote 0
          • P
            Perry
            last edited by

            Yes
            Make a alias list of lan ip's
            control there wan ip with your gateway settings on your lan rules

            /Perry
            doc.pfsense.org

            1 Reply Last reply Reply Quote 0
            • X
              xbr
              last edited by

              Thank you very much for replaying.

              i can choose only one gateway in my lan rules (default or wan interfaces' gateway so every ip can only point to one gateway).

              For example i have apache server running lets say on 192.168.2.100 port 3112,
              port forwarding  WAN  TCP  3112  servers (ext.: 213.197.143.21) 3112
              Setting wan rule  TCP  *  *  servers  3112  * 
              And it does not work.
              (as in testing mode in servers alias i added only one ip .2.100)

              1 Reply Last reply Reply Quote 0
              • P
                Perry
                last edited by

                Those extra public ip's you have, needs to be added under firewall -> virtual ip's

                /Perry
                doc.pfsense.org

                1 Reply Last reply Reply Quote 0
                • X
                  xbr
                  last edited by

                  yes. but now i set up one ip on my wan interface, and testing everything with several pcs only on one ip. (now wan ip is actualy 213.xxx.xxx.21 )

                  1 Reply Last reply Reply Quote 0
                  • P
                    Perry
                    last edited by

                    hmm sounds like dhcp to me.
                    Is the wan assign with dhcp or a static ip?
                    The wan should be assign with it's proper subnet mask ( CIDR). /30 in this case (someone correct me if I'm wrong)
                    http://www.subnet-calculator.com/cidr.php

                    /Perry
                    doc.pfsense.org

                    1 Reply Last reply Reply Quote 0
                    • X
                      xbr
                      last edited by

                      static.
                      everything is working except port forwarding. cant forward 213.xxx.xxx.21:4331 to 192.168.2.100:4331 (in my case)

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        Things regarding virtual IPs are often not working due to arpcache issues of the devices in front of you. Try to reboot the device in front of you or take down the line for some minutes to make the arp caches expire.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.