Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Public VLAN routing via pfSense with limited FW rules for selected VLANs?

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 4 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dotdashD
      dotdash
      last edited by

      MON=Manual Outbound NAT. He's just saying if you want traffic from each vlan to use different public IPs outbound, you have to do that manually.

      1 Reply Last reply Reply Quote 0
      • G
        Gio
        last edited by

        @dotdash:

        MON=Manual Outbound NAT. He's just saying if you want traffic from each vlan to use different public IPs outbound, you have to do that manually.

        Got it! Thanks. I will try tonight again

        Also I own the pfSense Definitive guide book (for old 1.2.3) and in there it says on page 148 that FTP proxy will be needed even on NAT 1:1 to public ips. is this statement is still accurate or should pfsense just pass traffic for destination public /29 to the right VLAN without any intervention or FTP proxy needed based on IP destination header? Trying to understand the logic of FTP proxy (makes sense if pf is the outbound NAT but since public IPs are the outbound NAT I don't see why FTP proxy is still needed on the WAN interface?)

        1 Reply Last reply Reply Quote 0
        • P
          podilarius
          last edited by

          FTP proxy should probably not used. I am not for my FTP server. But I guess it really depends on the FTP server that you are using. Mine is vsftpd and I have just configured NAT address and a small port range for passive ftp.

          1 Reply Last reply Reply Quote 0
          • G
            Gio
            last edited by

            What I have tried so far:

            • Disabling Packet Filtering (so that I can find out if its a routing issue or FW)
            • Enabled Manual NAT (deleted all automatically created routes)
              – Windows host under VLAN won't get a response from its gateway after that

            it looks like pfSense is not forwarding ip packets? (if its only a router with a default gateway set shouldn't it allow IP forwarding??)

            Thanks in advance. I can't get these hosts to be completely accessible from the internet (even with Packet filtering disabled) any quick and dirty guides to setup pfsense as router only with vlans? I could use that to setup a basic router then move on to packet filtering.

            1 Reply Last reply Reply Quote 0
            • G
              Gio
              last edited by

              I wonder if the reason why I can't get 1:1 outbound NAT to work is because I haven't clicked this checkbox in System > Advanced

              Automatically create outbound NAT rules which assist inbound NAT rules that direct traffic back out to the same subnet it originated from.
              Currently only applies to 1:1 NAT rules. Required for full functionality of NAT Reflection for 1:1 NAT.

              1 Reply Last reply Reply Quote 0
              • dotdashD
                dotdash
                last edited by

                Reflection is for bouncing the public IP back to the private IP. eg- If I'm at 192.168.1.100 and the webserver for www.company.com is at 192.168.1.50, but I'm trying to go the the public IP, it will bounce the traffic back to 192.168.1.50.
                Your goal is to take the /24 and break off four /29's, assigning each to a separate vlan, then use public IPs on the machines?

                1 Reply Last reply Reply Quote 0
                • G
                  Gio
                  last edited by

                  @dotdash:

                  Your goal is to take the /24 and break off four /29's, assigning each to a separate vlan, then use public IPs on the machines?

                  This is exactly what I am trying to achieve.

                  I am also unsure if I should turn off "LAN" interface since I am doing VLANs for everything. Not sure if this is one of the reasons I'm having trouble achieving what I want. LAN is setup as 172.16.0.1 and /24 DHCP server is on, all untagged traffic (other ports on switch) can get IP from the DHCP scope. VLANs are working as expected though I use STATIC IPs on VLANs no DHCP FYI

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gio
                    last edited by

                    Let me give you guys some more information about the setup. I will use random public IPs as example to get the idea accross, but same subnet and IP just masking the first 3 octets of my range.

                    WAN IP

                    • Gateway IP (default route) 199.10.20.97
                    • WAN IP config set to static with IP 199.10.20.98 255.255.255.252

                    LAN IP em0

                    • Static IP 172.16.0.1 /24
                    • DHCP server is running on this

                    VLAN10 (off em0)

                    • Static IP 200.44.32.129 - gateway 200.44.32.129 - netmask 255.255.255.248 (/29)

                    VLAN10 client

                    • Windows server 2003 - static IP 200.44.32.130 - gateway 200.44.32.129 netmask 255.255.255.248
                    1 Reply Last reply Reply Quote 0
                    • W
                      wallabybob
                      last edited by

                      I was redirected to this topic from http://forum.pfsense.org/index.php/topic,61013.msg328872.html

                      Actual ping responses are far more informative than "cannot ping". So I don't have to go hunting through other topics on the same problem please provide the output of pfSense shell commands```
                      /etc/rc.banner
                      ifconfig -a
                      netstat -r -n
                      ping -c 5 199.10.20.97    # wan gateway
                      ping -c 5 8.8.8.8

                      
                      And please provide output of following ping commands (after any necessary IP address correction) run on the VLAN10 client:```
                      ping 200.44.32.129
                      ping 199.10.20.98
                      ping 199.10.20.97
                      ping 8.8.8.8
                      
                      1 Reply Last reply Reply Quote 0
                      • G
                        Gio
                        last edited by

                        Screenshot pack 1

                        ![4-11-2013 2-11-31 PM.png](/public/imported_attachments/1/4-11-2013 2-11-31 PM.png)
                        ![4-11-2013 2-11-31 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-11-31 PM.png_thumb)
                        ![4-11-2013 2-13-41 PM.png](/public/imported_attachments/1/4-11-2013 2-13-41 PM.png)
                        ![4-11-2013 2-13-41 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-13-41 PM.png_thumb)
                        ![4-11-2013 2-14-28 PM.png](/public/imported_attachments/1/4-11-2013 2-14-28 PM.png)
                        ![4-11-2013 2-14-28 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-14-28 PM.png_thumb)
                        ![4-11-2013 2-15-44 PM.png](/public/imported_attachments/1/4-11-2013 2-15-44 PM.png)
                        ![4-11-2013 2-15-44 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-15-44 PM.png_thumb)
                        ![4-11-2013 2-16-51 PM.png](/public/imported_attachments/1/4-11-2013 2-16-51 PM.png)
                        ![4-11-2013 2-16-51 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-16-51 PM.png_thumb)
                        ![4-11-2013 2-17-19 PM.png](/public/imported_attachments/1/4-11-2013 2-17-19 PM.png)
                        ![4-11-2013 2-17-19 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-17-19 PM.png_thumb)
                        ![4-11-2013 2-17-34 PM.png](/public/imported_attachments/1/4-11-2013 2-17-34 PM.png)
                        ![4-11-2013 2-17-34 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-17-34 PM.png_thumb)
                        ![4-11-2013 2-18-01 PM.png](/public/imported_attachments/1/4-11-2013 2-18-01 PM.png)
                        ![4-11-2013 2-18-01 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-01 PM.png_thumb)

                        1 Reply Last reply Reply Quote 0
                        • G
                          Gio
                          last edited by

                          Screenshot pack 2.

                          Please see my settings - as you can see Packet filtering is on, gateway appears to be setup properly and routes appear to be there. Problem is without any kind of filtering my VLAN with my public /29 should be able to freely have full network access inbound and outbound, this is not working.

                          ![4-11-2013 2-18-29 PM.png](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png)
                          ![4-11-2013 2-18-29 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png_thumb)
                          ![4-11-2013 2-18-29 PM.png](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png)
                          ![4-11-2013 2-18-29 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-29 PM.png_thumb)
                          ![4-11-2013 2-18-50 PM.png](/public/imported_attachments/1/4-11-2013 2-18-50 PM.png)
                          ![4-11-2013 2-18-50 PM.png_thumb](/public/imported_attachments/1/4-11-2013 2-18-50 PM.png_thumb)

                          1 Reply Last reply Reply Quote 0
                          • W
                            wallabybob
                            last edited by

                            If you haven't rebooted the pfSense box since you disabled the firewall I suggest you do so. It has been my experience that some major changes eemed to need a reboot to correctly take effect.

                            The configuration information you posted looks OK. How about the ping output I requested. I want to see what is reported by ping at each stage: nearest pfSense interface, pfSense WAN interface, upstream gateway, google DNS.

                            1 Reply Last reply Reply Quote 0
                            • P
                              podilarius
                              last edited by

                              I noticed that you have the FW off, so no rules are going to apply anyway. This means no NAT, FW, nothing, only routing. Since that is the case, it would seem that you probably have a basic routing problem. Can machines on your VLAN ping the WAN ip of pfSense, then, can they ping the WAN Gateway?

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.