Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need Help with NAT

    Scheduled Pinned Locked Moved NAT
    3 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      adambmedent
      last edited by

      Here is the scenario.  I am trying to NAT all of our employee vpn traffic outbound to a single address.  This seems to work out great for networks which are attached to pfsense but I can't get it to work for a network coming through pfsense.

      For example I have no issue with an outbound NAT rule translating 10.80.0.0/16 to my LAN interface.
      LAN   10.80.0.0/16 * 10.230.0.0/16 * * * NO

      I would like to do the same idea with another network, but this network is not a interface of pfsense.  Pfsense has a static route to get back to this network.
      LAN     192.168.170.0/24 *     10.230.0.0/16      *      *       *     NO

      For some reason I can't get the 192.168.170.0/24 to translate like the 10.80.0.0/16

      1 Reply Last reply Reply Quote 0
      • P Offline
        podilarius
        last edited by

        That rules should make it look like traffic from that network is coming from the LAN ip address. Have you run a network trace to make sure that this is not happening? There might be a routing issue that is preventing return traffic.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Interface Source Source Port Destination Destination Port NAT Address NAT Port Static Port Description

          Where is your nat address in those rules?

          If you see above I posted the headings from the nat rules, I don't do any natting on my lan side - but only from lan to wan.  But don't you still need a NAT address to use?  In my drop down you can pick the interface address or setup a different IP, yours is just showing *?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.