Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT only work in the PfSense BOX not other client in LAN [solved with 2.0]

    Scheduled Pinned Locked Moved NAT
    33 Posts 3 Posters 13.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Metu69salemi
      last edited by

      Does your modem get public ip with dhcp or do you have static ip-addresses

      1 Reply Last reply Reply Quote 0
      • S
        syedadi
        last edited by

        my modem was setting to put the IP staticaly

        1 Reply Last reply Reply Quote 0
        • M
          Metu69salemi
          last edited by

          What kind of connection you have to internet pppoe? or something else?

          1 Reply Last reply Reply Quote 0
          • S
            syedadi
            last edited by

            Yes PPPOE and the connection made in the modem

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by

              What if you change pppoe to the pfsense? and leave modem to be only mediaconverter(rj45 to rj11)

              1 Reply Last reply Reply Quote 0
              • S
                serangku
                last edited by

                thats double NAT
                you should make double port forward too …

                make pppoe dialed from pfsense, modem just on bridge
                so NAT only on pfsense box, thats easier to troubleshoot then

                1 Reply Last reply Reply Quote 0
                • S
                  syedadi
                  last edited by

                  @serangku:

                  thats double NAT
                  you should make double port forward too …

                  make pppoe dialed from pfsense, modem just on bridge
                  so NAT only on pfsense box, thats easier to troubleshoot then

                  What do you mean double NAT? i don't understand? how can it be so complicated in PF box, because when using Untangle BOX it doing just fine with a simple port forward…  :'(

                  1 Reply Last reply Reply Quote 0
                  • S
                    syedadi
                    last edited by

                    @Metu69salemi:

                    What if you change pppoe to the pfsense? and leave modem to be only mediaconverter(rj45 to rj11)

                    I can't do that because i've 5 IPs from that modem…if i removed it, that should be too complicated for me to used other IPs..

                    1 Reply Last reply Reply Quote 0
                    • M
                      Metu69salemi
                      last edited by

                      I've got also 5 static ip's and uncontinous block, but in same subnet so i created carp vips for the "extra ip's" fifth one was given in installation point so there was no need to create fifth carp vip.

                      Please read howto's those are really selfexplaining. And if don't want go todo that way, fine it's your decision, but then i'm not able to help you any further

                      1 Reply Last reply Reply Quote 0
                      • S
                        syedadi
                        last edited by

                        Thanks  :D

                        1 Reply Last reply Reply Quote 0
                        • S
                          syedadi
                          last edited by

                          still no luck for me to do the 'NAT'ing…i've try other distro, the NAT went smoothly with out any trouble..i need to setup the nat in the pfsense....  :'( now using built on Wed Aug 24 10:02:03 EDT 2011

                          1 Reply Last reply Reply Quote 0
                          • M
                            Metu69salemi
                            last edited by

                            Screenshots would do miracles

                            1 Reply Last reply Reply Quote 0
                            • S
                              syedadi
                              last edited by

                              this is my digram

                              How can i trace i NAT respond? so i can know where the problems is? The screen shoot for the firewall as the 1st page…

                              1 Reply Last reply Reply Quote 0
                              • M
                                Metu69salemi
                                last edited by

                                you don't have to keep public ip in your modem, unless you want to connect that from wan/lan

                                I tried earlier to say, that put anything what modem does into pfsense: pppoe authentication etc. so your modem is only a dummy media converter(from network jack to modem jack)

                                1 Reply Last reply Reply Quote 0
                                • S
                                  syedadi
                                  last edited by

                                  Thanks bro,

                                  So if i make the authentication form PfSense server; can i put other server to the modem because my modem have 4 more free ports and i have 4 more IPs…would the server have their own public-IP for this setup?

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    Metu69salemi
                                    last edited by

                                    Why you need to put them to modem, pfsense can handle all of those, within hardware limitations.
                                    Just draw a picture where you show what you have and what you want. That helps a lot to "design" your network and setup pfsense.

                                    As an example(my setup):

                                    internet -- modem -- pfsense -- lan1- lan3
                                    
                                    5 static ip's all handled from pfsense, with previous setups i had only one(smoothwall didn't handle more than one, and pfsense handle as many as you want)
                                    
                                    Before i got 4 extra ip's i worked that every different lan(lan1, lan2 & lan3) natted with one public ip, now i have each lan with own ip + two different public ip's for server usage.
                                    
                                    All servers are in lan1 as my own lan. Servers use different public ip's than the rest of lan1.
                                    
                                    

                                    I wrote this up only for show, that pfsense is capable doing lot if set it up

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      syedadi
                                      last edited by

                                      OK, i understand…

                                      i need more time for migrate to that setup...len me think 1st...so i need to add one more LAN in the pfsense.
                                      Thanks

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        syedadi
                                        last edited by

                                        OK….
                                        now i can put the NAT working port port scann only (port 80), when i used the http://www.yougetsignal.com/tools/open-ports/ the port is open, but then i try to access port 80 from the web-browser, it can't be display…how can i troubleshoot this?

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          syedadi
                                          last edited by

                                          Thanks all, the release version 2.0 has solved my problems…. =)

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.