Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port nat to subnet behind internal pfsense router

    Scheduled Pinned Locked Moved NAT
    5 Posts 3 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cubsfan
      last edited by

      I'm trying to setup port nats to some internal IP addresses behind an internal pf router

      public VIP – pf1 -- internal subnet -- pf2 -- second internal subnet (s2 - 10.50.0.0)

      pf2 has no nat rules and I can access the hosts on 10.50 from pf1 and from my internal subnet.  I setup port NATs on pf1 VIPs to the 10.50 addresses but it doesn't appear to work.  Can't connect externally, don't get anything logged in the firewall log and don't see any states open up on pf1.

      Should this work?

      thanks

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        That works, you need the normal port forward+rule on pf1, and a firewall rule on pf2's WAN to allow the traffic.

        1 Reply Last reply Reply Quote 0
        • C
          cubsfan
          last edited by

          @cmb:

          That works, you need the normal port forward+rule on pf1, and a firewall rule on pf2's WAN to allow the traffic.

          Have done it with other routers so I assumed there was no magic.  I will keep digging, I'm not sure what I'm missing.

          thanks

          1 Reply Last reply Reply Quote 0
          • P
            podilarius
            last edited by

            If you have switched to AON, then you are going to have to create a rule for pf2 subnet. Can you get to the internet from behind pf2?

            1 Reply Last reply Reply Quote 0
            • C
              cubsfan
              last edited by

              @podilarius:

              If you have switched to AON, then you are going to have to create a rule for pf2 subnet. Can you get to the internet from behind pf2?

              As it turns out I had the DNS record published incorrectly so I was beating on someone elses firewall trying to get in.  Fixed that up and everything works nicely, amazing what one digit will do to you.  I should have just stopped yesterday and gone home.

              -andy

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.