Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Do I need NAT?

    Problems Installing or Upgrading pfSense Software
    4
    7
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sensi
      last edited by

      Hello,

      I currently have a bonded ADSL service going to a FreeBSD/PF box that is connected to a 3Com vLan switch.

      I'm changing the ADSL provider and also going over to pfSense - the new broadband provider has asked me if I need NAT and, if so, do I have any special requirements.  My 'guess' is that I want it turned on and left as standard - am I right?

      I have said that VPN will be used (and I'll possible have to set this up in pfSense).

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        why to use isp to do the same job that pfsense will do. If you're meaning nat is the main question.

        in some occassions you can say to isp that you have very capable firewall so you don't need anything except line and ip's(ofcourse some speed) but anything else is done by yourselve.

        But there is also some cases when it's not feasible to say that to isp. and just ask what isp do for you.

        1 Reply Last reply Reply Quote 0
        • R
          richinspirit
          last edited by

          I agree with Metu69salemi.

          You do not "need" NAT from them. pfSense will handle NAT in your environment.

          In fact, having NAT on pfSense behind NAT provided by your ISP can cause problems, so you likely don't even "want" NAT from them.

          If you are going to run a service like VPN from pfSense, I would say you would want to be in control of all NAT behavior in your environment by using NAT only on your pfSense box.

          My $.02

          1 Reply Last reply Reply Quote 0
          • S
            Sensi
            last edited by

            So, not NAT on the incoming service is what I'll do.

            Many thanks

            1 Reply Last reply Reply Quote 0
            • S
              Sensi
              last edited by

              Getting a bit concerned here!!

              I've unpacked the goods - 3 x adsl routers/modems and 3 x sharedband units.  No bonder (I've got to use a normal switch apparently).  Do I still want the NAT & DHCP turned off in these modems/routers?

              1 Reply Last reply Reply Quote 0
              • Cry HavokC
                Cry Havok
                last edited by

                If the router/modem can be configured in Bridge mode then that is your simplest option. It avoids double-NAT, which can cause problems.

                1 Reply Last reply Reply Quote 0
                • S
                  Sensi
                  last edited by

                  Thanks Havoc

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.