Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1:1 NAT to VLAN IP or Port Forward?

    Scheduled Pinned Locked Moved NAT
    11 Posts 3 Posters 9.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Metu69salemi
      last edited by

      as a hint in beginning, you can use aliases to ease out your struggle

      
      1\. Phase Create Virtual ip: type ip-alias
      Goto Firewall:Virtual IPs and press +
      Choose IP Alias
      Interface: WAN
      IP Address: 50.x.x.85 /32
      Description: as you like
      
      2\. Phase Create Port Forward
      Goto Firewall:NAT:Port Forward and press +
      Interface: WAN
      Protocol: as you need, most likely TCP or TCP/UDP
      Destination: 50.x.x.85
      Destination port range: http (or if you need http and https you could do port alias, i also added other ports needed as ssh)
      Redirect target IP: 192.168.100.11
      Redirect target port: 80 or that same alias as earlier
      Description: as you like
      All the other settings are default
      
      3\. Phase Create Manual Outbound NAT
      Goto Firewall:NAT:Outbound and choose manual and save after that
      Press +
      Interface: WAN
      Protocol: Any
      Source: Type:Network / Address: 192.168.100.11 /32
      Source port: Empty
      Destination: Any
      Translation: 50.x.x.85
      port: Empty
      Description: as you like
      
      4\. Phase Move your just created MON-rule to the first of the list and apply changes
      
      

      After those, just save everything and apply changes. Remember to reset states
      You should be covered, if you do these with aliases, you can change public ip quite, if you doubt that ip is in use or it doesn't work

      1 Reply Last reply Reply Quote 0
      • T
        Technyne
        last edited by

        @Metu69salemi:

        as a hint in beginning, you can use aliases to ease out your struggle

        
        1\. Phase Create Virtual ip: type ip-alias
        Goto Firewall:Virtual IPs and press +
        Choose IP Alias
        Interface: WAN
        IP Address: 50.x.x.85 /32
        Description: as you like
        
        2\. Phase Create Port Forward
        Goto Firewall:NAT:Port Forward and press +
        Interface: WAN
        Protocol: as you need, most likely TCP or TCP/UDP
        Destination: 50.x.x.85
        Destination port range: http (or if you need http and https you could do port alias, i also added other ports needed as ssh)
        Redirect target IP: 192.168.100.11
        Redirect target port: 80 or that same alias as earlier
        Description: as you like
        All the other settings are default
        
        3\. Phase Create Manual Outbound NAT
        Goto Firewall:NAT:Outbound and choose manual and save after that
        Press +
        Interface: WAN
        Protocol: Any
        Source: Type:Network / Address: 192.168.100.11 /32
        Source port: Empty
        Destination: Any
        Translation: 50.x.x.85
        port: Empty
        Description: as you like
        
        4\. Phase Move your just created MON-rule to the first of the list and apply changes
        
        

        After those, just save everything and apply changes. Remember to reset states
        You should be covered, if you do these with aliases, you can change public ip quite, if you doubt that ip is in use or it doesn't work

        I have a question: The .85 IP is already in use on WAN, I'm attempting to use the .86 is this still the correct way to go?

        I have done this exactly as shown here for the .86 and reset the state table but still cannot access the machine, I have confirmed I can access the .100.11 from inside.

        Thanks,
        Davin

        1 Reply Last reply Reply Quote 0
        • M
          Metu69salemi
          last edited by

          try with .87 if .86 don't work, your modem might use it.

          and it will work with .85 if you don't have any use for http/https addresses on public ip with firewall management or in another system.

          1 Reply Last reply Reply Quote 0
          • T
            Technyne
            last edited by

            @Metu69salemi:

            try with .87 if .86 don't work, your modem might use it.

            and it will work with .85 if you don't have any use for http/https addresses on public ip with firewall management or in another system.

            Hi,

            I am certain .86 is not in use, we have a /28 with .81 as the gateway. For the .85 I have port forwards in use already. The only IPs in use on this block is the .85 and .82, I need to assign forwards for .84 and .86.

            Any other options I can try?

            Thank you for your help!

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by

              reboot :D
              Can your firewall ping to your server?

              1 Reply Last reply Reply Quote 0
              • T
                Technyne
                last edited by

                @Metu69salemi:

                reboot :D
                Can your firewall ping to your server?

                Rebooted, no change. Can ping from PFSense Ping Tool.

                Ping output:
                
                PING 192.168.100.11 (192.168.100.11) from 192.168.15.1: 56 data bytes
                64 bytes from 192.168.100.11: icmp_seq=0 ttl=128 time=0.331 ms
                64 bytes from 192.168.100.11: icmp_seq=1 ttl=128 time=0.226 ms
                64 bytes from 192.168.100.11: icmp_seq=2 ttl=128 time=0.223 ms
                64 bytes from 192.168.100.11: icmp_seq=3 ttl=128 time=0.233 ms
                
                --- 192.168.100.11 ping statistics ---
                4 packets transmitted, 4 packets received, 0.0% packet loss
                round-trip min/avg/max/stddev = 0.223/0.253/0.331/0.045 ms
                
                
                1 Reply Last reply Reply Quote 0
                • M
                  Metu69salemi
                  last edited by

                  Then i must raise my hands, i don't know what is the problem. Sorry

                  1 Reply Last reply Reply Quote 0
                  • M
                    madboots
                    last edited by

                    Metu69salemi- Thanks, your instructions helped me out.

                    1 Reply Last reply Reply Quote 0
                    • M
                      Metu69salemi
                      last edited by

                      That's nice to hear.

                      And what is the OP's situation?

                      1 Reply Last reply Reply Quote 0
                      • T
                        Technyne
                        last edited by

                        Resolved, your instructions were correct. It turned out to be that the server in question did not have the correct gateway assigned. Thanks for your help!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.